CTIPilot
Sun · 13 Sep 2026
All daily briefs ↗
Daily brief · UTC day

Sunday, 13 September 2026

2 verified findings from 2 runs · 8 updates to prior coverage · the settled record for this UTC day, in the classic brief order.

Criticality
Kind
Topic
Region
TL;DR · the day in one read
  1. 01Anthropic discloses a Russia-linked actor whose AI agents detect their own malware getting caught and rebuild it, unattended. Anthropic's fourth threat-intelligence report (2026-09-10) profiles GTG-20006, a Russian cyber-espionage cluster it says is "consistent with public reporting linking the actor to Midnight Blizzard." The actor used Claude to build and operate device-code phishing infrastructure, execute intrusion commands directly against victims, and autonomously detect when its deployed malware was flagged by security products and rebuild it until it evaded detection again, across more than 20 government, military, diplomatic and drone-supply-chain organizations concentrated in Ukraine and Europe.
  2. 02Revolut handed over customer identity documents and crypto histories because the request came from an authentic-looking government email address. Revolut confirmed on 2026-09-12 that it disclosed customer KYC documents, selfies, IBANs and Bitcoin transaction histories to an unauthorized third party after an attacker submitted a fraudulent information request from an unauthorized mailbox operating inside a genuine government agency's own email domain. No Revolut system was breached and no malware was involved; the compromise was entirely of the process Revolut uses to verify inbound legal and regulatory data requests.

01Active threats, incidents & disclosures1 item

NOTABLEupdatedNATOB2

Revolut discloses a customer KYC data breach after fulfilling a fraudulent request sent from inside a genuine government agency's own email domain

Revolut confirmed to TechCrunch on 2026-09-12 that it disclosed sensitive customer data after receiving a fraudulent information request sent from "an unauthorised email account sent directly using the official government agency's email domain" (Revolut, via Security Affairs, 2026-09-12); Security Affairs assesses the attacker either registered a rogue mailbox within that domain or compromised an existing one. Because the message carried valid domain-authentication credentials, Revolut's compliance and KYC-response process treated it as authentic and fulfilled it: exposed data included full name, date of birth, occupation, postal and email address, phone number, passport or driver's-licence copies, verification selfies, IBAN and account statements, withdrawal records and full transaction history including Bitcoin (Security Affairs, 2026-09-12). No Revolut system was compromised and no malware was involved; the entire incident was a social-engineering compromise of the legal and regulatory data-request channel rather than a technical intrusion. Revolut says a "limited" number of customers were affected and declines to name the government agency, the country, or the customer count. Revolut discovered the fraud only when it independently contacted the agency to verify the request and was told the agency never sent it; it has since blocked the sending mailbox and notified the agency, law enforcement and financial regulators.

The same weakness applies to any organization whose legal or regulatory data-request process trusts that a request's sending domain is proof of the sender's authority: an attacker who obtains or spoofs access to a single mailbox on that domain can submit an urgent, seemingly authentic request that bypasses the normal verification a company would otherwise apply. Here that pattern reached a major fintech's KYC/AML compliance channel, and the entire compromise happened at the request-verification step: no phishing link was clicked and no credential was stolen, only an email that domain-authenticated correctly and asked for the right kind of data in a plausible way.

For any organization that operates a legal or regulatory data-request intake process, the transferable lesson is that domain-level email authentication (the same trust SPF, DKIM and DMARC exist to establish) is not proof of institutional authority: an adversary who controls, or convincingly spoofs, a single mailbox on a trusted government or law-enforcement domain can defraud any recipient who verifies a request only by checking that it came from the right domain. This cuts both ways for a public-sector authority: any authority that itself issues legal data requests to third parties (banks, telcos, cloud providers, ISPs) as part of investigations should assume that a compromise of its own mail infrastructure could be used to defraud those third parties in its name, and should expect the recipients of its own legitimate requests to apply out-of-band verification rather than treat that as an insult to its authority.

Revolut received a request for customer information that appeared to come from a legitimate government agency. The request came from an unauthorised email account sent directly using the official government agency's email domain.

As the communication carried valid domain authentication credentials, it was fulfilled under the reasonable belief that it was an authentic government agency request.

Revolut (customer notification, via Security Affairs)

Revolut recently identified a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information.

Revolut spokesperson, via TechCrunch
Correctionrun 2026-09-13T1307Z-auditbody

The quotation from Revolut's customer notification in the opening paragraph was rendered with an inserted ellipsis. Revolut's sentence reads in full: "The request came from an unauthorised email account sent directly using the official government agency's email domain" (Revolut, via Security Affairs, 2026-09-12). The two elided words are the operative ones for a defender reading this as a control failure: the request was sent directly from the agency's own domain rather than from a lookalike, which is why domain authentication passed and why the sending domain told Revolut's reviewer nothing about the sender's authority.

incident13 Sep 04:37Zsingle-source · victim disclosureOpen finding ↗

02Updates to prior coverage8 items

HIGHCVE-2026-50656 +1updatedNATOB2

ShieldBreak, a public proof-of-concept defeats Microsoft's July fix for the RoguePlanet Defender flaw, claims 100% reliability where the original was a coin flip, and now covers Windows Server 2025

First published 2026-08-12 · open finding →

Updaterun 2026-09-13T1307Z-auditheadlinesummarytagscvesactionssourcesevidencebody

Microsoft has shipped a fix. Its own record for CVE-2026-69414 names Malware Protection Engine 1.1.26080.3 as the first version with the vulnerability addressed and 1.26070.7 as the last affected, so this entry's standing "no fix available" statement is superseded and the frontmatter, headline, summary and action item move with it. Separately, on 2026-09-08 the same researcher published ShieldCrash, claiming the fix is incomplete under specific conditions; that claim is the researcher's own, relayed by SOCRadar, carries no new CVE, and Microsoft has not confirmed it. Surfaced by this audit's coverage re-sweep.

Microsoft has shipped a fix, and this entry's standing "no fix available" status was stale. Microsoft's own record for CVE-2026-69414 now carries a remediation boundary in its structured fields: "Last version of the Microsoft Malware Protection Engine affected by this vulnerability" reads 1.26070.7, and "First version of the Microsoft Malware Protection Engine with this vulnerability addressed" reads 1.1.26080.3 (Microsoft MSRC, latest revision 2026-09-03). The record's CVSS vector carries RL:O (an official fix) against the E:P proof-of-concept maturity it already had. The practical point for a defender is that the Defender engine version updates on its own cadence and is not the same thing as the OS patch level, so an estate that is fully current on Windows Update is not thereby on engine 1.1.26080.3; check the engine version explicitly. That replaces detection-as-the-only-control, which is what this entry has told readers since 2026-08-12.

The same researcher now claims the fix is incomplete, as their own claim, not a confirmed one. On 2026-09-08 Nightmare Eclipse published ShieldCrash, described in the researcher's own repository as a partial rather than total bypass: "Microsoft has failed to properly patch ShieldBreak CVE-2026-69414, under specific conditions it is still possible to trigger the exact same problem that was caused by ShieldBreak. While Microsoft fixed several things to prevent re-exploiting the issue, they missed a spot where ShieldBreak can still be exploited" (Nightmare Eclipse, 2026-09-08). What is published is explicitly unfinished and narrower than the original: SOCRadar records that "ShieldCrash does not currently have a separate CVE. Nightmare Eclipse describes the public release as a skeleton PoC that demonstrates privileged file reads. It does not establish arbitrary file writes or SYSTEM-level code execution" (SOCRadar, 2026-09-10), and that "Microsoft has not publicly confirmed the reported bypass" (SOCRadar, 2026-09-10). Microsoft's record predates the ShieldCrash release by five days and acknowledges no bypass. SOCRadar also states there is no confirmed in-the-wild exploitation of ShieldCrash.

HIGHCVE-2026-80172 +3updatedNATOA2

Dell Secure Connect Gateway DSA-2026-382: an unauthenticated request replayed indefinitely mints ADMIN tokens, and Dell ships no workaround for any of the 105 flaws

First published 2026-09-06 · open finding →

Improvementrun 2026-09-13T1307Z-auditbody

The body described DSA-2026-382 as being "in its only revision to date". Dell's own revision history now lists a second revision, 2.0 of 2026-09-07, whose stated scope is "Formatting changes without any updates to data". No CVE, score, affected or fixed version, or workaround statement differs between the two revisions, so nothing else in this entry is affected; the phrasing is corrected so a reader comparing against the live advisory is not misled.

Dell has published a second revision of DSA-2026-382 since this entry was written. Revision 2.0, dated 2026-09-07, is recorded in the advisory's own revision history as "Formatting changes without any updates to data" (Dell PSIRT). Nothing a defender acts on has moved: the 105 proprietary-code CVEs, the three scoring 9.0 or above, the affected and fixed versions, and Dell's record of the available workarounds as None were all re-checked against the current advisory and are unchanged. The note is here so that a reader comparing this entry against a live advisory that now reads "Revision 2.0" does not conclude the entry is describing a superseded document.

NOTABLEupdatedNATOB2

Japan's Digital Agency: a VPN vulnerability exploited since May went undetected for a month, surfaced only by an anomalous mass file-access alert on a maintenance account, exposing ~246,000 government-personnel records

First published 2026-09-12 · open finding →

Correctionrun 2026-09-13T1307Z-auditclassificationsourcing_note

Admiralty credibility lowered from 1 to 2. All three cited sources relay the Digital Agency's single 2026-09-11 press release and press conference rather than assessing the incident independently, which is the one-assessor-several-publishers pattern the classification rule scores as 2. The sourcing note's claim that Jiji Press and the Piyolog-relayed agency statements are independent of each other is corrected with it.

The confidence this entry conveyed in its Admiralty rating was too high, and the reason matters for how a reader weighs it. Every fact here traces to one disclosure: the Digital Agency's 2026-09-11 press release and the accompanying press conference. Jiji Press, Piyolog and Rocket Boys Security Measures Lab each report that announcement; none of them examined the intrusion. Independent corroboration means a second party that observed or assessed the thing, not a second outlet that republished the first, so the credibility number is 2 (probably true, not independently confirmed) rather than 1. Nothing factual in the entry changes, the figures, the scope and the agency's statements were re-verified against the same sources and hold. What changes is that a reader should treat the account as the Digital Agency's own, still awaiting outside confirmation: the VPN vendor, the product, the CVE and whether the flaw was known and patched before the intrusion all remain undisclosed by any party.

HIGHCVE-2026-81963 +1exploitedupdatedNATOA1

September 2026 Patch Tuesday: two actively exploited Windows privilege-escalation zero-days (CVE-2026-81963 Update Stack, CVE-2026-85880 ALPC)

First published 2026-09-09 · open finding →

Correctionrun 2026-09-13T1307Z-auditsummarybody

The count of CVEs fixed in Microsoft's September 2026 Patch Tuesday was stated as "roughly 1,170". No source this entry cites carries that figure: BleepingComputer reports 966 and Zero Day Initiative writes "nearly 1,000". Corrected to 966, cited to BleepingComputer. The two exploited zero-days, their scores, their KEV listings and every other claim in the entry are unaffected and were re-verified against the MSRC per-CVE records and the KEV catalog.

This entry gave the size of the September 2026 Patch Tuesday as "roughly 1,170" fixed CVEs. That figure is not supported by either source cited for it. Microsoft shipped fixes for 966 flaws, which BleepingComputer calls "a record-breaking 966 flaws" (BleepingComputer, 2026-09-08), and Zero Day Initiative opens its review with "nearly 1,000 CVEs coming out from Microsoft" (Zero Day Initiative, 2026-09-08). The corrected count changes nothing operational: the two exploited zero-days, their CVSS 7.8 scores, and their 2026-09-08 KEV listings were re-verified against Microsoft's per-CVE records and CISA's catalog and all hold.

NOTABLEupdatedNATOB2

Revolut discloses a customer KYC data breach after fulfilling a fraudulent request sent from inside a genuine government agency's own email domain

First published 2026-09-13 · open finding →

Correctionrun 2026-09-13T1307Z-auditbody

The body rendered Revolut's notification with an inserted ellipsis that dropped the words "sent directly" from the middle of the quoted sentence. The full sentence is restored. The elided words carry the operative detail: the fraudulent request was sent directly from the government agency's own domain, not merely styled to resemble it.

The quotation from Revolut's customer notification in the opening paragraph was rendered with an inserted ellipsis. Revolut's sentence reads in full: "The request came from an unauthorised email account sent directly using the official government agency's email domain" (Revolut, via Security Affairs, 2026-09-12). The two elided words are the operative ones for a defender reading this as a control failure: the request was sent directly from the agency's own domain rather than from a lookalike, which is why domain authentication passed and why the sending domain told Revolut's reviewer nothing about the sender's authority.

HIGHCVE-2026-85706 +2exploitedupdatedNATOA1

CVE-2026-85706, GitLab CE/EE: unauthenticated path traversal in the repository commits API reads arbitrary server files, and honeypots caught exploitation attempts one day after the patch (CVSS 10.0)

First published 2026-09-12 · open finding →

Updaterun 2026-09-13T0409Z-intelcvestagsbody

NCSC Switzerland's own advisory independently confirms CVE-2026-87719 (CVSS 9.9, GitLab EE only), an insecure-deserialization flaw already described in this entry but not previously given its own CVE record; this update adds one, alongside a further EE-only flaw from the same patch release, CVE-2026-88765 (CVSS 8.5, vendor-sourced only), a buffer overflow reachable via a crafted Git project import.

NCSC Switzerland's own advisory, published 2026-09-11, independently confirms CVE-2026-87719 (CVSS 9.9, GitLab EE only) alongside CVE-2026-85706 in the same posting. GitLab's own release notes describe the flaw: "GitLab has remediated an issue that, under certain conditions, could allow an authenticated user with Duo Chat access to obtain Advanced Search instance configurations and sensitive credentials using a specially crafted GraphQL subscription argument to bypass serialization and perform server object lookup" (GitLab, 2026-09-10). Affected versions are EE only, 18.3 up to the same 19.1.8/19.2.6/19.3.2 fixed releases already named in this entry; no exploitation is confirmed for this CVE. The same release also fixed CVE-2026-88765 (CVSS 8.5, GitLab EE only, sourced from GitLab's own release notes alone with no independent confirmation found): "GitLab has remediated an issue that, under certain conditions, could allow an authenticated user to achieve remote code execution by importing a specially crafted Git project export to overflow the Unicode conversion buffer used in Advanced Search indexing" (GitLab, 2026-09-10). This flaw's affected-version floor, EE 12.3, is substantially older than the other two flaws in this release, so any EE instance that has deferred upgrades for a long period carries the largest exposure window for this specific remote-code-execution path.

Audit logs for GraphQL subscription requests with abnormal argument shapes targeting Advanced Search, and for an Advanced Search reindex operation immediately following a Git project import from an external or untrusted source, are the discriminators for these two additional flaws.

HIGHCVE-2026-85046 +2exploitedupdatedNATOB1

BlueMoon: five separate state-nexus actor clusters independently weaponize a shared Chrome V8 + Windows kernel zero-day chain within one week

First published 2026-09-10 · open finding →

Updaterun 2026-09-13T0409Z-inteltitleheadlinesummarycvesentitiestechniquesreferencessourcesclassificationsourcing_notebody

NCSC Switzerland's own advisory names Government among the sectors this exploit chain has targeted (no Swiss victims reported so far), and Volexity's technical write-up supplies the chain's missing middle CVE (CVE-2026-87491, a WebAssembly sandbox escape) and a fifth operator, UTA0560, which deploys a distinct in-memory JScript backdoor (GRIMWEDGE); Volexity also names JungleBamboo's (APT31) malicious-extension loader (SUPERSTOMP) and the extension itself (LONGTALE).

NCSC Switzerland's own Cyber Security Hub advisory lists this chain's targets so far as "NGO, Government, Consulting, Finance, Mining, Commodity Trading" while stating no case has yet been reported in Switzerland (NCSC Switzerland, 2026-09-12). Volexity's own technical write-up, cited in that advisory, supplies the exploit chain's previously missing middle link: "the exploit first gains arbitrary read/write within the V8 sandbox through the Type confusion vulnerability (CVE-2026-85046), then combines a separate WebAssembly defect to escape the V8 sandbox (CVE-2026-87491)," before the Windows kernel flaw completes the escape to full code execution in the browser process (Volexity, 2026-09-09). Volexity names a fifth operator, UTA0560, which reached the chain through a reflected cross-site-scripting flaw on a legitimate US university website, unlike JungleBamboo's own delivery via attacker-registered domains fronted by Cloudflare Tunnels, and deployed GRIMWEDGE, an in-memory JScript backdoor under 250 lines that runs as an evaluated string inside msiexec.exe. Delivery chains through a dropper (msgbox.exe) that sideloads wsc.dll; wsc.dll beacons to a per-victim URL keyed on hostname to fetch and launch the next-stage MSI payload via msiexec.exe, and GRIMWEDGE itself, once running, instead sends HTTP POST requests carrying the victim's domain, username and prior command output to a single fixed command-and-control URL, with server responses evaluated as script; GRIMWEDGE supports ten commands including file read/upload, process control and command execution. Volexity separately documents JungleBamboo's (APT31/TA412) own payload chain: a loader it names SUPERSTOMP tampers with Chrome's Secure Preferences file, stripping and forging the per-preference integrity values to smuggle in a malicious extension impersonating "Google Gemini" past Chrome's own tamper checks; the resulting extension, LONGTALE, keylogs every keystroke and form or clipboard value across all open tabs, steals cookies and web-storage tokens, and takes keyword-triggered screenshots, exfiltrating collected data roughly every 30 seconds. This mechanism and disguise match Proofpoint's own GemStone/GhostChrome-X description of the same actor's tooling closely enough that the two vendor names may describe the same artifact rather than two distinct ones; neither vendor's own report confirms this directly, so both names are carried here without merging them.

An unexpected process loading wsc.dll and beaconing outbound over HTTPS to a per-hostname URL path, followed shortly by an msiexec.exe process installing whatever that beacon returned, is UTA0560's dropper-stage signature; a msiexec.exe process making repeated outbound HTTP POST requests to the same fixed destination with no corresponding user-initiated software installation is the discriminator for the GRIMWEDGE backdoor stage that follows it. A Chrome extension whose Secure Preferences integrity hash was set by a process other than Chrome itself, or that requests clipboard and all-tab permissions while impersonating a well-known AI-assistant name, is JungleBamboo's LONGTALE signature. Both persistence mechanisms, like the original entry's, survive the underlying browser and OS patches untouched.

HIGHCVE-2026-20079exploitedupdatedNATOA1

CVE-2026-20079, Cisco Secure Firewall Management Center: unauthenticated authentication bypass to root, unpatched for five months and only exploitable in a post-boot window (CVSS 10.0)

First published 2026-08-04 · open finding →

Updaterun 2026-09-13T0409Z-intelentitiestechniquestagsevidencesourcesbody

Cisco Talos named three distinct post-compromise clusters exploiting this CVE and its sibling CVE-2026-20316: one deploying a web shell for credential theft, one assessed to overlap in tooling with Sandworm and deploying a Cyclops Blink variant, and one deploying Qilin-affiliate ransomware. Cisco's own advisory was separately revised to confirm it became aware of active exploitation in August 2026, and Cisco has scheduled a further hardening release for 2026-09-16.

Cisco Talos confirmed active exploitation by three distinct post-compromise clusters (Cisco Talos, 2026-09-09). UAT-12197 exploited this CVE alone, planting a JSP web shell in the CSM Tomcat webroot and a JAR-based command executor used to query the FMC's internal user database for credentials (Cisco Talos, 2026-09-09). UAT-11823 exploited both this CVE and CVE-2026-20316 together; Talos states the cluster "overlaps in tooling with the Sandworm APT actor" (Cisco Talos, 2026-09-09), replacing the appliance's license.tmp file with a malicious root-executed package before deploying a variant of Cyclops Blink, the modular implant the US and UK previously attributed to Sandworm. UAT-11988 entered via CVE-2026-20316's static credential alone and, after AD/MySQL credential harvesting, tunnel-based lateral movement and disabling security tooling, deployed ransomware whose subsequent actions Talos found "were consistent with those of Qilin ransomware affiliates" (Cisco Talos, 2026-09-09). Cisco's own advisory was separately revised (v2.5, 2026-09-09) to confirm it became aware of active exploitation of this vulnerability in August 2026 (Cisco PSIRT, 2026-09-09), and Cisco has scheduled a further comprehensive Secure FMC/ASA/FTD hardening release for 2026-09-16 (Cisco PSIRT advance notification, 2026-09-09).

A JSP file appearing in the CSM Tomcat webroot, or a JAR-based executor querying the FMC's own user database, is UAT-12197's signature; a Cyclops Blink deployment resolves its command-and-control address over DNS-over-HTTPS rather than a hardcoded address, so DoH lookups from the FMC management-plane process are a discriminator; and a SOCKS5 proxy or reverse-SSH tunnel originating from the FMC and forwarding LDAP, LDAPS, Kerberos, SMB or NetBIOS/WinRM traffic toward the internal directory is UAT-11988's lateral-movement signature, worth treating as an active-compromise indicator whether or not ransomware has yet deployed.

03Deep dive1 item

HIGHNATOA2

GTG-20006: a Russian espionage cluster runs AI-orchestrated intrusions and autonomously rebuilds detected malware across 20+ government, military and drone-supply-chain targets

Anthropic's own threat-intelligence report names GTG-20006 ("GTG" for Generative Threat Group) as a Russian cyber-espionage cluster whose "attribution is consistent with public reporting linking the actor to Midnight Blizzard" (Anthropic, 2026-09-10), an overlap assessment rather than a firm identity claim. One operator uses the handle "JackPoterz," described as "a Russian speaker...whose tradecraft and targeting are consistent with Russian state-nexus espionage" (Anthropic, 2026-09-10). What distinguishes this cluster from a conventional espionage operation is how much of the intrusion lifecycle Claude itself carried out rather than merely assisted: the actor used it to build and operate device-code phishing infrastructure abusing legitimate cloud-email sign-in flows, to execute portions of intrusions directly against victim systems (running commands, harvesting credentials, moving laterally under the actor's direction), to organize and process hundreds of gigabytes of exfiltrated data, and to automate maintaining persistence across compromised tenants by registering actor-controlled devices.

The kill chain, as Anthropic's report and the operator's own toolkit describe it: initial access runs through device-code phishing against legitimate cloud-email sign-in flows, tricking a victim into authorizing an actor-controlled device (a technique that bypasses password prompts and most multi-factor challenges by design). From an authorized device, the actor registers further devices to keep tenant access alive independent of any single compromised credential, then uses AI-directed commands to harvest additional credentials and move laterally. Collection runs through remote email collection at scale, the actor "bulk-exported the mailboxes of at least two drone component manufacturers, targeted a military drone maker, and stole a complete proprietary software development kit for a drone vision system" (Anthropic, 2026-09-10), alongside a credential-stealing tool that targets browser password stores. The actor also took over victims' WhatsApp accounts by linking them as companion devices through a headless-browser platform built on the open-source WPPConnect automation library, suppressing read receipts so the bulk export of Russian- and Ukrainian-language conversations went unnoticed, targeting at least two former senior Ukrainian officials this way; separately, it found authorization flaws in camera-streaming-service APIs and harvested tokens granting access to victims' live camera feeds (Anthropic, 2026-09-10). A custom toolkit supports the operation: Windows implants PowerChrome, WUEngine, Shadow C2, MiniPlasma and CloudSyncSvc; an Android RAT, GiftDrop; and an iOS exploit chain, DarkSword. Anthropic's investigation "identified more than 20 distinct organizations targeted in the actor's operational planning, reconnaissance, and live operations," naming "government ministries, defense and intelligence bodies, embassies and diplomatic missions, think tanks, and defense-industrial companies, concentrated in Ukraine and Europe but extending to the Middle East and maritime related government agencies in Asia" (Anthropic, 2026-09-10); a North African government technology authority lost more than 300,000 national identity records and commercial-registry data on half a million companies through a compromised VPN appliance, and a secondary, recurring target class was the military-drone supply chain.

The operationally novel piece is the evasion loop: "the actor also used AI to monitor how well their tools evaded detections from known security defenses. If their monitoring AI agents identified that any of their deployed malware was detected by a security product, agents would then set about the process of autonomously modifying and rebuilding the malware to evade the existing detections" (Anthropic, 2026-09-10). This closes a loop that previously required a human malware developer's turnaround time between a detection event and a re-armed sample, compressing the defender's usual advantage of "we caught it once, it's caught for good" into something the actor can iterate against automatically. The same cluster also compromised at least three hospitality-sector WiFi vendors to DNS-hijack hotel guest traffic and stage ClickFix-style malware lures against Ukraine-linked travelers (Anthropic, 2026-09-10); the same hospitality-network technique the referenced CaptiveCrunch entry covers Microsoft attributing, in July 2026, to Storm-2945, an operational sub-cluster of Midnight Blizzard. Anthropic states its report-wide mitigation posture as: "In each case, we disrupted the activity, used what we learned to strengthen our safeguards, and shared intelligence with authorities and industry partners, where appropriate" (Anthropic, 2026-09-10).

Hunt and detection concepts, telemetry class first: device-code authentication flows are rare in most enterprise environments outside specific CLI/IoT scenarios, so cloud-identity audit logs recording a device-code grant, followed shortly by a new device registration on the same tenant, is a strong anomaly signal worth alerting on regardless of the account's apparent legitimacy. Mailbox-level audit logs showing a bulk export or unusual volume of message reads across a short window, especially against accounts tied to procurement, engineering or supply-chain functions, match this actor's collection pattern. On the endpoint side, any of the named implant families persisting via a scheduled task, service, or registered device that was not provisioned through the organization's normal device-management workflow is worth a compromise assessment. For any organization operating in a sector this actor has already targeted (government, defense-industrial, diplomatic, drone/UAV supply chain), the standing lesson is that AI-agentic tradecraft is no longer a theoretical risk category: detection engineering and incident response should assume an adversary can iterate on a caught sample within the same operational window a defender is still investigating it, and hunt playbooks should include recently-modified or newly-compiled variants of previously blocked families rather than relying on static signature coverage alone.

GTG-20006 is an actor who has increased their speed by automating their operations using AI. Our attribution is consistent with public reporting linking the actor to Midnight Blizzard.

One of the operators is a Russian speaker using the handle "JackPoterz" whose tradecraft and targeting are consistent with Russian state-nexus espionage.

Our investigation identified more than 20 distinct organizations targeted in the actor's operational planning, reconnaissance, and live operations. They included government ministries, defense and intelligence bodies, embassies and diplomatic missions, think tanks, and defense-industrial companies, concentrated in Ukraine and Europe but extending to the Middle East and maritime related government agencies in Asia.

A secondary recurring target for theft was drone supply chain technology. The actor bulk-exported the mailboxes of at least two drone component manufacturers, targeted a military drone maker, and stole a complete proprietary software development kit for a drone vision system.

The actor also used AI to monitor how well their tools evaded detections from known security defenses. If their monitoring AI agents identified that any of their deployed malware was detected by a security product, agents would then set about the process of autonomously modifying and rebuilding the malware to evade the existing detections.

In each case, we disrupted the activity, used what we learned to strengthen our safeguards, and shared intelligence with authorities and industry partners, where appropriate.

The actor also took over victims' WhatsApp accounts, using a platform of headless browsers to link victim accounts as companion devices.

They found authorization flaws in the application interface of camera streaming services, and from there they enumerated users and harvested tokens that granted them access to the victims' live camera streams.

Anthropic 2026-09-10

Builds on: 2026-08-01/captivecrunch-storm-2945-hospitality-captive-portal-rat

threat13 Sep 04:37Zsingle-sourceOpen finding ↗
Verification & coverage notes2 runs

2026-09-13T1307Z-audit · audit · Opus 5 · window 168 h · 0 entries published

Verification & coverage notes

Audit report: docs/audits/2026-09-13-quality-audit.md. Window 2026-09-06T13:08Z → 2026-09-13T13:07Z (168.0 h), anchored on the previous audit record's started; seven intel fires; 50 entries in scope (26 published new, 24 older entries carrying an in-window changelog record).

Soundness: 42 of 50 entries verified clean, 2 factual errors, 6 imprecisions. The two factual errors are the September 2026 Patch Tuesday CVE count on 2026-09-09/windows-september-2026-two-exploited-lpe-zero-days-kev (stated "roughly 1,170"; BleepingComputer says 966 and ZDI "nearly 1,000", and 1,170 appears in neither) and the EPSS probability on 2026-07-24/laundry-bear-zimbra-zero-click-cve-2025-66376 (0.1201 against FIRST.org's 0.21621 for the entry's own dates, a magnitude error the 2026-09-06 audit's unit-only conversion carried forward). Both corrected through the entry's changelog.

The window's headline finding is that the verifier can be blocked reproducibly by content. The 2026-09-09T1726Z-intel fire published two entries with iterations: [] after four cti-verification spawns were terminated by the content-safety classifier, and its record asked the next audit for an independent pass. This audit attempted it and reproduced the trip three more times across three further framings, the full 15-entry batch (killed mid-flight), a 7-entry defensive-fact-checker reframe with manifest-file scope (killed on spawn), and the 2 entries alone with per-entry checkpointing (killed on spawn), while two sibling batches covering the other 13 entries of the same split completed normally. Seven blocked spawns across two fires and four framings establishes the trip as a property of the content, not the message. The main agent verified the three uncovered entries itself (batch D: the two 2026-09-09 entries plus 2026-09-12/jfrog-artifactory-…, which the first-pass inventory had missed) and found a factual error in one of them (the Patch Tuesday count above) while confirming everything else those entries claimed against MSRC per-CVE records, the KEV catalog, MITRE CNA records and the cited primaries.

Completeness inside the window: no gap. The mechanical KEV sweep found 14 in-window additions and 0 uncovered, every row resolving to a named entry, the second consecutive clean KEV window. G1 returned zero new items; G2 one borderline (Oomnium, a Zurich crowdfunding platform, correctly out of nexus); G3 thirteen candidates, all either already covered, correctly droppable under the v4.2 quality-over-quantity bar, or a development on a covered finding.

Two pre-window findings the re-sweeps surfaced. First and more serious: 2026-08-12/shieldbreak-defender-rogueplanet-patch-bypass-no-fix has told readers since August that no fix exists for CVE-2026-69414, in its headline, summary, action item and twice in its body. Microsoft's own record has named the fix since 2026-09-03, Malware Protection Engine 1.1.26080.3, with 1.26070.7 the last affected, and RL:O in the vector. That is the defect class where the whole remediation inverts. Fixed by an update record that moves the status, names the fixed engine build, rewrites the stale statements where they stand, and replaces the action item with an explicit engine-version check (the Defender engine updates on its own cadence and is not the OS patch level). The same record carries the ShieldCrash development with its attribution intact: a partial bypass claimed by the researcher's own repository, no new CVE, explicitly unfinished, and not confirmed by Microsoft.

Second: CVE-2026-27912 (ResetNightmare) entered state/cves_seen.json on 2026-08-09 and no entry ever covered it. Opened as a recovery candidate on the strength of its index title (Kerberos, low-privileged user to Domain Admin) and closed as a correct drop by the primaries: Microsoft patched it in April 2026, rates it CVSS 8.0 AV:A/…/E:U/RL:O, sets exploited: No and "Exploitation Less Likely", and it is not on CISA KEV, PD-11(b)'s excluded case. The in-window 0patch backport reaches only unsupported Windows Server estates under a third-party patch subscription, too narrow for an entry under the v4.2 bar. No entry recovered; the deep read is persisted under work/ so a future fire need not redo it. What it exposed is that nothing checks the index-into-entries direction (253 ids store-wide sit in that gap, mostly legitimately) raised as operator recommendation 2.

Entries updated (8), all through their changelogs, none silently: four correction records (Windows Patch Tuesday count; Zimbra EPSS, internal; Japan Digital Agency credibility 1→2 with its sourcing note; Revolut spliced quotation), three improvement records (Dell revision history; LiteLLM KEV citation, internal; NetScaler live-counter as_of, internal) and one update record (ShieldBreak / ShieldCrash). No entry was published new.

Fixes shipped. Prompts to v4.10 in lockstep with a CHANGELOG entry: a new exhausted-ladder rung in Phase 5.7 requiring the main agent to take the truth half of the gate on its own output when every spawn is blocked, and to record what it did and could not do; the "one iteration is mandatory" hard rule fenced to name that single exception. tools/check_run.py carries store severity for verification.iterations missing or empty under --all only (run scope still FAILs, tested against the 2026-09-09 record) because a published record is immutable and fail() never consults the acknowledgment ledger, so the FAIL was permanently unclearable. tools/kev_window_diff.py gains --run-id and writes work/<run-id>/kev-window.txt itself, because fourteen fires across two windows were asked to tee that file and none did.

Source-health work. The NCSC.ch carry-forward watch item is resolved and the recipe was genuinely broken: both BACS pages are Nuxt SPAs returning an empty shell to their recorded transports, which is why they stayed green at seven and six quiet periods while contributing nothing since 2026-06-18; ncsc-ch-incidents had its own note recording that the bridge returned "a JS-only shell" and was never switched. Both now pinned to the transport verified to hydrate them. The previous audit's recommendation 3 is discharged three of four: Volexity and Proofpoint were never broken (an RSS hunt on a feedless host, and a WebFetch summariser eating a listing), SocRadar works with its listing-date metadata recorded as unreliable, GreyNoise re-confirmed; Aqua Nautilus is not a record in sources/sources.json at all. ReliaQuest, IBM X-Force and Jamf Threat Labs are confirmed dark across extract, jina and bridge url and left active rather than demoted, so the blind spot stays visible.

Warning sweep. One new acknowledgment (the 2026-09-09 empty verifier block, with the reproduction evidence and an explicit statement of the fix deliberately not taken); existing 31 rows reviewed, none dead, none pruned; ledger now 32. check_run.py --all ends 0 warn · 0 fail (32 acknowledged) and site/build.py emits no self-check warnings.

  • Reduced-confidence note (aggregator-only, the check's own documented disposition): 2026-09-13/revolut-fake-government-request-kyc-breach cites two news hosts and no vendor or regulator primary. That is inherent to the story rather than a sourcing shortfall, every fact traces to Revolut's own customer notification and spokesperson statement, which is the PD-5 victim carve-out the entry already records as verification: single-source-victim, and no regulator has published. Carried as-is.
  • Monthly priority calibration: not due; the 2026-09-06 report carries the September section. Context only: high ran 63.6 % of operational entries this window (n=22) against a store-wide 51.7 %, with three criticals; flagged for the October pass, and no mis-prioritized entry was found among them.
  • Coverage gaps: inside-it-ch returns HTTP 429 site-wide on every transport (Insel Gruppe still blocked on it); urnerzeitung.ch 403; netzwoche.ch has no feed; reliaquest, ibm-xforce and jamf-threat-labs serve content-free shells.
  • ATT&CK pin: attack_data.py --check reports up to date, local v19.2 == upstream latest v19.2.
  • Watchdog: no fire in the window tripped the runaway-duration threshold, against five the previous window; the longest was 2.90 h.

2026-09-13T0409Z-intel · Sonnet 5 · window 26 h · 2 entries published

Verification & coverage notes

Standard window (gap since the previous run about 24.0 hours, 26-hour recency window); today (2026-09-13) is a Sunday and the general threat-research publishing landscape was genuinely quiet in-window across the home-region/sector, research and incident domains, most sources' newest items clustered 2026-09-09 through 2026-09-11, confirmed by broad supplementary searches, not a fetch-tooling failure. No closed-source intake drops this run. No product/supplier watchlist configured in this deployment; the sector lens and general relevance discipline were applied throughout.

Two updates recover apparent gaps from the last three daily fires, disclosed transparently. A sweep of NCSC Switzerland's Cyber Security Hub surfaced two in-window (2026-09-11/2026-09-12) NCSC-CH advisories whose own cited primaries (Cisco Talos, Volexity) were dated 2026-09-09, a day or two outside the strict 26-hour window on their own. Given the NCSC-CH advisories themselves are in-window, the underlying material is a material development on two already-critical/high-severity, actively-exploited entries already carried here (the Cisco Secure FMC auth-bypass chain and the BlueMoon exploit kit) rather than a new, isolated finding, and leaving a verified, high-severity gap unrecovered when it is already in hand would be a blind spot on critical/high signal, both were composed as update records rather than held. A third update (GitLab CVE-2026-87719 / CVE-2026-88765) closes a narrower gap: CVE-2026-87719 was already named in the existing entry's own analysis but had never carried its own CVE record, and CVE-2026-88765 is a genuinely new same-release finding, both independently confirmed by NCSC Switzerland (for the former) and GitLab's own release notes.

One new entry rides the wider window this pipeline allows for an actively developing story, disclosed for the same reason. Anthropic's own GTG-20006 threat-intelligence report (published 2026-09-10, with edits as late as 19:29Z the same day) sits inside that wider window but outside the strict 26-hour one; it was fully verified against Anthropic's own primary plus two independent secondaries (The Hacker News, 2026-09-11; UNITED24 Media, 2026-09-12), confirming continued press attention through 2026-09-12 as the in-window hook. This is a globally significant, fully-verified nation-state AI-misuse campaign (Russia-linked, Midnight Blizzard overlap, 20+ government/military/diplomatic/drone-supply-chain targets) with no existing coverage here, and was selected as today's deep dive (category: apt-campaign) given its technical depth and defender-relevance to any organization's AI-agentic threat model.

  • borderline-drop: Peter Gutmann's heise online interview naming "stunt cryptography" (CVE disclosures engineered for academic/media visibility over real exploitability), a genuinely interesting, single-source commentary/analysis piece on the CVE-disclosure ecosystem itself, not a technical vulnerability or threat-actor finding; it does not clear the relevance gate as tradecraft or detection-relevant analysis, and the quality-over-quantity bar resolves this doubt toward drop.
  • Coverage-backlog: all twelve open rows re-checked this run at the standing low/cheap-recheck budget (Siemens S7 PLC advisory, Insel Gruppe/ServiceNow, Ixa Systems/TheGentlemen, UICC/Krybit, Kairos/Ville de Libercourt, VMware VMSA-2026-0007, Spring Ring, three residual research items, NovoCure, Medela/ShinyHunters, SafePay/reichenau.at, Ville du Tampon); no row cleared its blocking condition this run. One new row opened: GTG-27005 (same Anthropic report as today's deep dive, a freelance Russia-based team's autonomous drone-swarm targeting software), noted but not yet verified to full primary-source depth.
  • Essential-coverage: missed=cisa-directives (persistent recipe gap, every transport tried returns only the site's filter-facet shell; no structured CISA directives feed exists yet).
  • Aggregator-only sourcing (acknowledged, not fixed): the Revolut entry cites TechCrunch and Security Affairs only. The entry's actual primary is Revolut's own customer notification and spokesperson statement, quoted independently by both outlets; Revolut has published no reachable newsroom statement of its own (checked: revolut.com/newsroom/ 404s). This is the established single-source-victim carve-out; the entry already carries the corresponding verification value and a sourcing note naming the gap; not re-pivoted or dropped.
  • Coverage gaps: reliaquest (client-rendered blog, the reader fallback resolved to an unrelated ad-tracker pixel); ssd-disclosure (individual advisory pages returned a browser-challenge page this run, though the listing itself was readable); tp-link-omada-psirt (URL now 404s, needs a canonical-URL probe); fortiguard.com FG-IR-26-164 through -174 (anti-bot challenge on every transport; CERT-FR's own advisory confirms the CVE list but carries no CVSS or exploitation-status detail).