Weekly review

ThreatNoir Morning Brief — September 14

2026-09-14Morning4 articles
Audio
Listen to the episode

Morning Review in IT Security — September 14, 2026

September 14, 2026 brings critical security developments across multiple fronts, with nation-state threat actors actively exploiting vulnerabilities in widely deployed enterprise and consumer software. Organizations face mounting pressure to patch critical flaws in VPN infrastructure, remote access tools, and supply chain components while defending against sophisticated exploit kits targeting zero-day vulnerabilities.

Hackers Exploit Tencent App Flaw to Deploy GrayRabbit Malware

Threat actors linked to a China-aligned espionage group are actively exploiting a critical vulnerability in Tencent's Sogou Input Method for Windows to deploy the GrayRabbit backdoor. The vulnerability, tracked as CVE-2026-51990, represents a significant risk to Windows users who rely on this widely used input method application. The exploitation campaign demonstrates how threat actors continue to target popular software components that may be overlooked in security patching routines.

Source: Bleeping Computer

CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV

The U.S. Cybersecurity and Infrastructure Security Agency has added five security flaws to its Known Exploited Vulnerabilities catalog following confirmed reports of active exploitation. The affected products include JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS, all critical components in enterprise infrastructure. The vulnerabilities tracked as CVE-2026-42016, CVE-2026-42018, CVE-2026-67277, CVE-2026-82329, CVE-2026-84869, and CVE-2026-86060 span multiple severity levels, with CVE-2026-42016 carrying a CVSS score of 8.1. The inclusion in CISA's KEV catalog signals that these flaws are being weaponized in the wild and require immediate patching.

Source: The Hacker News

Dutch NCSC: Critical Check Point VPN Flaws Exploitation is Imminent

The Dutch Nationaal Cyber Security Centrum is warning of imminent exploitation of two critical vulnerabilities in Check Point VPN solutions. The flaws, identified as CVE-2026-85102 and CVE-2026-85103, pose a direct threat to organizations relying on Check Point infrastructure for secure remote access. The warning from a national cybersecurity authority underscores the urgency of deploying patches before threat actors begin widespread exploitation campaigns.

Source: Bleeping Computer

BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days

Multiple espionage-motivated threat actors have adopted the BlueMoon exploit kit in opportunistic and rushed deployments targeting critical zero-day vulnerabilities. The toolkit chains recent Chrome and Windows zero-days, identified as CVE-2026-85046, CVE-2026-85880, and CVE-2026-87491, to maximize impact against unpatched systems. The rapid adoption by multiple threat actors indicates that BlueMoon represents a significant escalation in the threat landscape, enabling less sophisticated attackers to execute complex multi-stage attacks.

Source: SecurityWeek

Closing Perspective

Today's threat landscape reflects a coordinated campaign by nation-state and espionage-motivated actors to exploit both known vulnerabilities and zero-day flaws across enterprise and consumer platforms. Organizations must prioritize immediate patching of Check Point VPN, ScreenConnect, Artifactory, and RouterOS systems while monitoring for exploitation attempts targeting Chrome, Windows, and Tencent applications.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV
CVE6
  • JFrog Artifactory improper authentication vulnerability
  • JFrog Artifactory incorrect authorization vulnerability
  • ConnectWise ScreenConnect improper privilege management and missing authorization vulnerability
  • MikroTik RouterOS missing authentication for critical function vulnerability
  • MikroTik RouterOS improper neutralization of argument delimiters in a command vulnerability
  • Previously added Artifactory vulnerability used in chaining attacks