< ciso
brief />
Crypto Heist, Exploited Flaws, and New Cloud Security Controls

Crypto Heist, Exploited Flaws, and New Cloud Security Controls

Coverage: 25 Sept 2026 – 27 Sept 2026 (UTC)

< view all daily briefs >

A major cryptocurrency theft, fresh exploitation warnings, and several security-focused cloud updates defined the day. Investigations continue into a nine-figure exchange breach, while defenders face active attacks against enterprise software and edge appliances. At the same time, large providers introduced controls aimed at hardening identity, encryption, bot defense, storage operations, and disaster recovery.

Major Intrusions and Theft

The Hacker News reports that cryptocurrency exchange Bitget disclosed a $351.6 million theft from its hot and warm wallets, detected after a wave of unauthorized transfers. Bitget said cold wallets and most platform assets were not impacted, deposits and trading remain operational, and withdrawals were paused pending a comprehensive review. The company engaged incident responders Mandiant and SlowMist, noted that assets and chains affected include ETH, XRP, BNB, AVAX, USDT, and USDC across Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base, and stated the attacker compromised a critical backend wallet system to spoof transaction data and bypass authorization. Bitget added that its self-custodial Bitget Wallet infrastructure was not affected and that some chain foundations have frozen addresses; on-chain and IP patterns were described as consistent with North Korea–linked activity.

CSO Online details a campaign observed by Gambit in which an attacker used open-source AI tooling to target 105 online retailers over several weeks, successfully breaching 27. The operator utilized tools labeled Strix (discovery), Cairn (autonomous exploitation), and Hermes (orchestration) via OpenRouter, spending about $7,005 in total—roughly $25 per target—while often obtaining access within hours. Outcomes included the theft of roughly 600,000 active credit card records at two businesses, card skimmer implants at others, and at least some degree of access to multiple large companies. Gambit contacted affected organizations and underscored how accessible AI services can increase the speed and efficiency of intrusion operations.

The Hacker News also covers Ontinue’s analysis of the Psychedelic (LunexStealer) information stealer delivered via compromised Ukrainian sites, click-through CAPTCHA pages, and trojanized MSI installers. The chain employs LunexLoader to bypass UAC using the CMSTPLUA COM object, then executes a bring-your-own-vulnerable-driver technique with a Radeon kernel driver (PDFWKRNL.sys, CVE-2023-20598) to blind security tools before deploying the stealer. The malware targets seven Chromium-based browsers for credentials and cookies, enumerates multiple desktop and extension wallets, achieves persistence via registry, a hidden scheduled task, and a Chromium native messaging host, and injects a malicious Chrome extension by altering Secure Preferences. Ontinue notes kernel callback modification was used to neutralize detection and that common mitigations did not block the specific driver variant used.

Exploited Vulnerabilities and Immediate Actions

BleepingComputer reports that CISA added multiple vulnerabilities to its Known Exploited Vulnerabilities catalog, including CVE-2026-5430 in WSO2 products (authentication bypass enabling forged JWTs) and CVE-2026-71362 in Adobe Commerce/Magento (incorrect authorization allowing attacks without accounts or user interaction). CISA also highlighted a high-severity Microsoft SharePoint code injection issue (CVE-2026-65660) and an SSH workflow bypass in MikroTik RouterOS (CVE-2026-67279). Federal agencies are directed to apply vendor updates, mitigations, or discontinue affected products by late-September deadlines; CISA urges all organizations to prioritize remediation. Researchers observed real-world activity targeting WSO2 and Adobe Commerce, and the agency emphasized potential impact in sectors where WSO2 is widely deployed.

Kaspersky highlights CVE-2026-87902, a critical WordPress vulnerability affecting versions 4.7.0 through 7.1.1 that permits arbitrary PHP file inclusion outside the intended theme directory. Under certain configurations this enables remote code execution; WordPress issued security updates on September 22 and provided patched builds across supported branches, with 7.1.2 or later as the latest stable. Exploit attempts were observed within hours of patch release, and third parties have documented indicators of compromise; administrators are advised to update immediately and consider additional hardening guidance as supplemental measures.

The Hacker News relays watchTowr’s disclosure of two unpatched remote code execution zero-days in Citrix NetScaler ADC and NetScaler Gateway under active exploitation. Citrix had not yet confirmed details or issued mitigations at the time of reporting; some administrators have isolated or powered down appliances while awaiting guidance. The issues are described as separate from an August authentication bypass (CVE-2026-19490), with affected builds not yet clarified. Organizations weighing operational risk are advised to treat devices as potentially compromised, follow vendor recommendations for suspected compromise (evidence preservation, isolation, credential rotation, key and certificate revocation), and ensure management interfaces are not exposed to the internet.

Cloud Security Controls and Resilience

AWS post — IAM outbound identity federation now supports Amazon VPC interface endpoints for OIDC discovery and JWKS verification key retrieval via AWS PrivateLink. This enables workloads in isolated VPCs without internet egress to validate short-lived JWTs from AWS STS privately, helping align with stringent network and compliance requirements across all commercial AWS Regions, AWS GovCloud (US), and China Regions. AWS post — Amazon Transcribe adds support for customer-managed KMS symmetric keys to encrypt custom vocabularies, vocabulary filters, and custom language models at rest. Customers gain explicit key-permission control, CloudTrail auditing of key use, and the ability to disable or rekey resources to revoke access on their timeline.

AWS post — AWS Elastic Disaster Recovery now supports AWS Graviton-based (arm64) source servers. DRS automatically detects arm64 workloads and recovers them onto compatible Graviton instances using the same workflows as x86, extending recovery coverage across heterogeneous environments at no additional charge where DRS is available. Cloudflare — Turnstile Spin automates correct end-to-end integration of the Turnstile privacy-first, puzzle-free challenge by directing a coding agent to locate frontend and backend code, propose changes, and apply them locally with user approval. Spin supports new deployments, fixes missing server-side validation, and migrations from other CAPTCHA providers, without sending application code to Cloudflare.

Google Cloud — Storage Intelligence advisor is now GA, surfacing daily findings on cost and risk signals (e.g., operation spikes on cold storage, 429 errors, cross-region egress, anomalous consumption) and tying them to buckets, prefixes, and service accounts within 24 hours. Expanded batch operations convert recommendations into serverless jobs to update storage classes, apply retention or encryption policies, and mass-delete objects at scale, with multi-bucket processing, dry-run validation, and advanced CEL filters; a 30-day trial is available. Google Cloud — Memorystore for Valkey 9.1 is GA, delivering up to 3x QPS with microsecond latency via a lock-free, multi-queue architecture and dynamic scaling. The release adds database-level ACLs with centralized management and audit logging, CLUSTERSCAN, and new commands (HGETDEL, MSETEX, and conditional HSETEX), plus expanded node SKUs and a managed migration workflow from self-managed Redis/Valkey.

Enterprise Platform and Ecosystem Shifts

BleepingComputer notes Microsoft’s plan to deprecate Windows Deployment Services (WDS) beginning with the next Windows Server release. The inbox WDS role, services, tools, management interfaces, and WDS-provided PXE boot will be marked deprecated, with functionality persisting on currently supported Windows Server versions until end of servicing. Non-Microsoft deployment tools and independent PXE solutions that do not depend on WDS are unaffected, and Microsoft Configuration Manager OS deployment remains supported; customers relying on WDS-backed PXE or multicast are advised to plan migrations.

BleepingComputer reports Anthropic opened the public Claude Marketplace with more than 2,000 listings spanning integrations, plugins, connectors, agents, and partner-built products. Listings include offerings from major vendors and partners and support open publishing via the Model Context Protocol and Agent Skills. The stated goals are streamlined discovery, direct access to Claude users for partners, and expanded functionality beyond basic integrations; the marketplace is live for enterprises and developers.

Crypto Heist, Exploited Flaws, and New Cloud Security Controls · CISO Brief