Weekly review

ThreatNoir Morning Brief — September 16

2026-09-16Morning4 articles
Audio
Listen to the episode

Morning Review in IT Security — September 16, 2026

The cybersecurity landscape continues to face escalating threats from nation-state actors and active exploitation of critical vulnerabilities. Today's review highlights concerning developments involving Iranian state-sponsored malware operations, zero-day attacks against enterprise infrastructure, and active exploitation of widely deployed software platforms.

Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists

Cybersecurity agencies in the United States, the United Kingdom, and the Netherlands have jointly detailed a Windows malware attributed to Iran's intelligence service that targets dissidents, journalists, and activists globally. The malware, identified as CHOSEN BRICK and HEAVYGRAM, operates through Telegram command and control channels, enabling remote operators to exfiltrate sensitive communications and surveillance data.

The malware's capabilities extend beyond simple data theft, with functionality to copy emails and chat messages, capture screenshots, and remotely activate microphones for audio recording. This sophisticated approach demonstrates Iran's continued investment in surveillance infrastructure targeting vulnerable populations and those critical of the regime. Source: The Hacker News

Cisco Warns Customers of Actively Exploited Zero-Day in Email Gateways

Cisco has confirmed that a zero-day vulnerability in its email gateway products was actively exploited in the wild before patches became available. The company disclosed the flaw tracked as CVE-2026-76461 but provided limited details regarding the nature of attacks or the extent of customer impact.

The exploitation of email gateway infrastructure represents a significant risk vector, as these systems typically control inbound communications for entire organizations. The lack of detailed disclosure regarding attack scope suggests the vulnerability may have affected a substantial portion of Cisco's customer base. Source: CyberScoop

Cyber Operation Targets South Korean Media and Automotive Sectors

A likely North Korean advanced persistent threat group has deployed a previously undocumented Linux espionage toolkit in coordinated attacks against South Korean media and automotive companies. The threat actors focused on compromising load balancers to gain network access and establish persistent footholds for further exploitation.

This campaign demonstrates North Korea's continued focus on critical infrastructure and information gathering from economically significant sectors. The use of previously unknown malware tooling suggests ongoing development of specialized capabilities targeting Linux environments. Source: Dark Reading

Acronis Warns of Actively Exploited Flaw in cPanel Backup Plugin

Acronis has disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager, and Plesk platforms, with evidence of active exploitation. The vulnerability, identified as CVE-2026-87886, allows attackers to escalate privileges on affected systems.

Given the widespread deployment of these hosting control panels across web hosting providers globally, this vulnerability poses significant risk to countless websites and applications. Organizations running Acronis backup solutions should prioritize patching efforts immediately. Source: Bleeping Computer

Organizations face mounting pressure to address multiple critical vulnerabilities and nation-state threats simultaneously. Prioritizing patches for actively exploited flaws while strengthening defenses against sophisticated state-sponsored malware remains essential for enterprise security postures.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).