DEV Community

NetSecOpsIO
NetSecOpsIO

Posted on Originally published at cyber.netsecops.io

Daily Cybersecurity Intelligence - September 22, 2026

Daily cybersecurity intelligence digest from CyberNetSec.io - September 22, 2026


📊 8 threat intelligence reports covering vulnerabilities, exploits, threat actors, and security advisories.


1. RatHat Android Malware Uses AI to Steal Banking Credentials

Security researchers have uncovered a sophisticated Android remote access trojan (RAT) named 'RatHat,' attributed to Chinese threat actors. The malware uses generative AI to dynamically navigate infected devices, bypassing traditional security measures. Distributed via smishing and fake app stores, RatHat tricks users into granting extensive accessibility permissions, enabling it to activate wireless debugging, gain shell access, and deploy overlays to steal credentials, PINs, and MFA codes. Its persistence mechanisms make a factory reset the only reliable removal method.

📖 Read full report →


2. SideCopy APT Group Targets Indian Academia with ReverseRAT

The Pakistan-nexus threat group SideCopy has broadened its targeting from Indian government and military entities to include academic institutions. A new campaign uses spear-phishing emails with malicious LNK files to deliver the ReverseRAT trojan. The attack chain involves using 'mshta.exe' to execute a remote HTA file, which reflectively loads a DLL. Persistence is achieved via a Registry Run Key, and the final ReverseRAT payload is loaded into memory using .NET deserialization to evade detection. The C2 infrastructure reuses domains previously linked to the group.

📖 Read full report →


3. BigCommerce Breach Linked to Compromised Ribon App Key

E-commerce platform BigCommerce has disclosed a data breach affecting an undisclosed number of its merchants. The incident was a supply-chain attack originating from a compromised application key for the third-party 'Ribon' and 'Ribon 1.5' apps. Attackers used this key to access customer data between September 13 and 17, 2026. Exposed data includes customer names, emails, phone numbers, and shipping addresses. Financial data was not affected. One victim, Master of Malt, has notified its customers and the UK's ICO.

📖 Read full report →


4. CISA's Cyber Storm X Tests Critical Infrastructure Resilience

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has concluded Cyber Storm X, its tenth biennial national cyber exercise. The four-day event involved over 2,000 participants from government and private sectors, simulating a sophisticated nation-state attack on U.S. critical infrastructure. This year's scenario focused on the transportation (rail and ports) and water/wastewater systems sectors. The exercise aimed to test incident response plans, improve coordination, and strengthen information-sharing channels. CISA will publish an after-action report with findings and recommendations.

📖 Read full report →


5. Rapuncel Infostealer Disables EDR via Signed Kernel Driver

A new information stealer dubbed 'Rapuncel' is being distributed through a widespread campaign that uses fake, SEO-optimized GitHub repositories impersonating LastPass and 39 other brands. The malware's most dangerous feature is a malicious kernel driver, 'Alinubx.sys,' which is signed with a valid Microsoft certificate. This driver acts as an 'EDR killer,' terminating 145 different security products to operate undetected. Once security is disabled, Rapuncel steals credentials from browsers, cryptocurrency wallets, and applications like Discord and Steam.

📖 Read full report →


6. Haruko Crypto Firm Breach Affects 15 Institutional Clients

London-based crypto infrastructure provider Haruko has suffered a cyberattack affecting 15 of its institutional clients. An attacker exploited an internal vulnerability to steal a user-access token from a process's memory. This token was then used to capture read-only API keys and trading data for clients who had not enabled IP whitelisting. Despite the keys being read-only, some smaller hedge-fund clients reportedly lost funds, suggesting potential security control weaknesses on their end. Haruko has since patched the vulnerability and rotated its secrets.

📖 Read full report →


7. Elsevier Domain Hijack Redirects to LAPSUS$ Page

Three domains belonging to academic publisher Elsevier, including Elsevier.com, were temporarily hijacked on September 21, 2026. For at least 78 minutes, visitors were redirected to a webpage branded with the name of the LAPSUS$ extortion group. The page taunted the FBI and featured a countdown timer. The hijack was likely executed via a compromised DNS or CDN configuration, with unverified claims pointing to a modified Cloudflare redirect rule. The domains have since been restored, and there is no confirmed link between this activity and the original LAPSUS$ group.

📖 Read full report →


8. ShinyHunters Takes Over Clop Ransomware Leak Site

In a rare public display of infighting, the ShinyHunters extortion group has hijacked the dark web data leak site of the notorious Clop ransomware gang. ShinyHunters defaced the site, claiming the takeover was retaliation for Clop's alleged theft of a zero-day exploit for Oracle's E-Business Suite. ShinyHunters has threatened to release data on Clop's operations, including lists of victims who paid ransoms. The incident highlights the volatile and competitive nature of the cybercrime ecosystem.

📖 Read full report →


📌 Subscribe to daily updates at CyberNetSec.io

All reports include detailed analysis, IOCs, mitigation strategies, and references.

Top comments (0)