Daily cybersecurity intelligence digest from CyberNetSec.io - September 25, 2026
📊 9 threat intelligence reports covering vulnerabilities, exploits, threat actors, and security advisories.
1. n0n Ransomware Group Adds Backup Destruction to Extortion Tactics
A new ransomware group tracked as 'n0n' is escalating its extortion model by not only stealing data but also threatening to encrypt or destroy victim backups. First observed in mid-September 2026, the group has already listed over a dozen victims on its dark web leak site, primarily targeting the financial services, technology, and retail sectors. The group's initial access vector relies on compromised credentials, highlighting the need for robust identity security and isolated backup strategies.
2. ShinyHunters Targets Healthcare with Aggressive Vishing Campaigns
The healthcare and pharmaceutical industries are under siege from a wave of sophisticated social-engineering attacks, particularly voice phishing (vishing). A Health-ISAC advisory warns that threat actors, including the notorious group ShinyHunters, are using aggressive phone tactics and medical-themed domains to trick employees into giving up credentials. The campaigns aim to cause operational downtime, which is becoming a primary extortion tactic against clinical environments.
3. WordPress Core Vulnerability CVE-2026-87902 Under Active Attack
A critical, unauthenticated path traversal vulnerability in WordPress Core, tracked as CVE-2026-87902 (CVSS 9.2), is being actively exploited in the wild. The flaw affects WordPress versions 4.7.0 through 7.1.1 and allows attackers to include local PHP files, which can lead to remote code execution (RCE) in certain configurations. Exploitation began just hours after disclosure, and all site owners are urged to update to version 7.1.2 or other patched versions immediately.
4. Actively Exploited Zero-Day (CVE-2026-94127) in F5 BIG-IP APM
F5 has released emergency patches for a critical zero-day vulnerability (CVE-2026-94127) in its BIG-IP Access Policy Manager (APM) that is being actively exploited. The flaw, a heap-based buffer overflow with a 9.8 CVSS score, allows unauthenticated remote code execution. It affects BIG-IP systems configured as OAuth Authorization Servers. Due to active exploitation, CISA has added it to its Known Exploited Vulnerabilities (KEV) catalog, mandating a rapid patch cycle for federal agencies.
5. Microsoft: Storm-2570 Affiliate Uses Same TTPs for Qilin, DragonForce
A Microsoft Threat Intelligence report details the activities of a single ransomware affiliate, Storm-2570, which has been observed deploying four different ransomware payloads: Qilin, DragonForce, Anubis, and BERT. The group maintains a consistent playbook of TTPs, including the use of RMM tools for C2, credential harvesting with Mimikatz, and data exfiltration with Rclone. This highlights the importance of tracking attacker behaviors over just the final malware payload for effective defense.
6. CISA and FBI Issue Guidance on Securing Third-Party ICS Access
CISA and the FBI have released a joint fact sheet advising critical infrastructure operators on reducing risks from third-party Industrial Control Systems (ICS) integrators. Prompted by a 2025 breach where foreign actors accessed an integrator's network, the guidance stresses the importance of least privilege, robust contract language, and diligent monitoring of remote access to prevent supply chain compromises in OT environments.
7. Threat Actor Uses AI Agents to Automate Breach of 100+ Companies
A Chinese-speaking threat actor has used a toolkit of commercially available AI agents to automate a massive campaign against online retailers, stealing over 600,000 credit card records. Research from Gambit Security revealed the campaign used AI frameworks like Strix and Cairn for reconnaissance and exploitation, costing as little as $25 per target. The attacks, which also involved deploying web skimmers and destroying data, targeted major companies including a Fortune 500 hospitality firm and a U.S. airline.
8. Windows Botnet x47.c Marketed with 'AI API Drain' Attack Method
A new Windows botnet dubbed 'x47.c' is being sold on dark web forums, featuring a novel attack method designed to drain victims' paid AI service credits. The botnet, offered by a threat actor named 'WraithTools,' can use a victim's stolen API keys to generate heavy, billable requests to services like OpenAI, causing financial harm in what is known as a 'denial of wallet' attack. The botnet also includes 17 other traditional attack methods like DDoS and credential theft.
9. SolarWinds Fixes RCE Flaws (CVE-2026-28324, CVE-2026-28325)
SolarWinds has patched two remote code execution (RCE) vulnerabilities in its Observability Self-Hosted platform. The most severe, CVE-2026-28324, is a critical (CVSS 9.8) insufficient integrity check flaw exploitable in non-default configurations. The second, CVE-2026-28325 (CVSS 8.8), is a deserialization flaw. Both can be exploited by an unauthenticated remote attacker. Customers are urged to update to version 2026.2.3 immediately.
📌 Subscribe to daily updates at CyberNetSec.io
All reports include detailed analysis, IOCs, mitigation strategies, and references.
Top comments (0)