In partnership with

~7 MIN READ
FACT
An autonomous AI agent framework assembled by hackers in under six hours stole thousands of employee credentials with no human operator after setup. A speed no human team could match. (Google Threat Intelligence Group Q3 2026 AI Threat Tracker)
The Signal
 
The perimeter is still shrinking, and this edition has a specific thread: the systems you outsourced trust to are failing in the ordinary spots. A skipped patch. A delayed disclosure. An unmonitored standalone box. Attackers found all three.

PS: Was this forwarded to you? Subscribe free at exzeccyber.com/subscribe

📌 Big Cyber News
 
Developer tools
🔧 JetBrains Got Hacked Through a Bug in JetBrains. The Credentials Your Pipeline Was Storing Are Gone.
Intro
The company that distributes the developer tools your team trusts just proved it doesn’t always apply its own security patches.
What Happened
Between August 8 and August 24, attackers exploited CVE-2026-63077, a critical unpatched TeamCity vulnerability, to breach Cadence, JetBrains’ own cloud compute service. They exfiltrated AWS IAM credentials, PyCharm project source code, S3 bucket contents, and a full 2024 server backup. JetBrains acknowledged the compromised server “should have been patched as part of its own vulnerability response efforts” but offered no explanation for why it wasn’t.
Why It Matters
AWS IAM credentials are skeleton keys. Anyone who used Cadence during that window should treat their cloud environment as potentially accessed. Supply-chain attacks begin exactly like this: a trusted tooling vendor gets breached, and the real target is everyone downstream.
The Other Side
JetBrains says the breach was limited to a defined group of Cadence users with no broader system impact. No downstream customer breaches have been confirmed yet.
 
👉 Takeaway
If your team used JetBrains Cadence between August 8 and August 24, rotate every connected credential now: AWS IAM, S3 bucket secrets, repository tokens, all of it.
TL;DR: JetBrains didn’t patch its own product inside its own cloud. Attackers walked in, and AWS credentials and source code left with them.
Further reading: The Hacker News

AI can build faster. Can your team decide better?

AI can draft the PRD and prototype the idea. Jira Product Discovery helps teams decide whether it belongs on the roadmap. Bring feedback and ideas together, prioritize as a team, and keep your roadmap connected to delivery in Jira.

🚨 Can’t Miss
 
 
Zero-Day
CVE-2026-75650 in Adobe Commerce and Magento Open Source has been exploited in the wild since September 4. Attackers are using it to install Rust-based backdoors that disguise command-and-control traffic as NTP requests, making them harder to detect at the network edge. Emergency hotfix VULN-39341 was released September 8 and is available from repo.magento.com. Every version from Adobe Commerce 2.4.4 through 2.4.9 and Magento Open Source 2.4.6 through 2.4.9 is affected, including builds that were fully patched before today’s release.
Apply the hotfix from repo.magento.com immediately. Exploitation was confirmed before the patch existed.
 
Data Breach
An unauthorized party accessed Thomson Reuters’ West Publishing C-Track platform from March through June 2026. Discovery was June 30; court notifications came weeks later. Exposed data includes SSNs, driver’s license numbers, medical records, and sealed or confidential court filings across 12 US states, the US Virgin Islands, and Canada. No attacker has been identified.
If you or clients have active cases in any of the affected jurisdictions, check whether sealed filings may be in scope.
 
Cybercrime
“ChatNoir,” the alias behind ZeroBytes, was arrested after breaching France’s tax authority and stealing records on 600,000 people: names, tax IDs, family details, and income data. He was under judicial supervision from two prior cases, including a breach of 19 million telecom subscribers. Both prior cases were handled as juvenile offenses. This one isn’t.
Three investigations, same attacker, now an adult. The arrest stands; the pattern is the more interesting signal.

Blu Dot surpasses 2,000% ROAS with self-serve CTV ads

Home furniture brand Blu Dot blew up on CTV with help from Roku Ads Manager. Here’s how:

After a test campaign reached 211,000 households and achieved 1,010% ROAS, the brand went all in to promote its annual sales event. It removed age and income constraints to expand reach and shifted budget to custom audiences and retargeting, where intent was strongest.

The results speak for themselves. As Blu Dot increased their investment by 10x, ROAS jumped to 2,308% and more page-view conversions surpassed 50,000.

“For CTV campaigns, Roku has been a top performer,” said Claire Folkestad, Paid Media Strategist, Blu Dot. “Comping to our other platforms, we have seen really strong ROAS… and highly efficient CPMs, lower than any other CTV partner we've worked with.”

Using Roku Ads Manager, the campaign moved from a pilot to a permanent performance engine for the brand.

🤖 AI in Cyber
 
 
Autonomous AI
Google’s Threat Intelligence Group documented a credential-harvesting campaign in which a financially motivated group assembled a multi-agent AI framework in under six hours. Once deployed, the framework scanned for targets, harvested credentials, troubleshot its own failures, and rotated IP addresses, all without a human operator in the loop. Thousands of credentials were stolen. The whole attack cycle completed faster than most incident response workflows can begin.
If your detection strategy assumes time to catch an intruder before data leaves, update it.
 
Vulnerability
Researchers at Manifold Security found that Git’s core.fsmonitor performance setting gets read by AI coding agents and can trigger attacker-controlled commands before trust prompts appear. Claude Code, Codex, Cursor, and Goose have shipped patches. Hermes Agent, Qwen Code, and Grok Build have not. Attack vector: a repository with an intact .git directory, opened locally. No network access needed.
Update your AI coding agent. Be cautious about opening repos from unfamiliar sources until all unpatched tools ship fixes.
🕵️ Threat Intel
 
 
Threat Actor
The KongTuke group, also tracked as Woodgnat, loads legitimate, signed Node.js installers to run malicious JavaScript payloads. The installers are trusted software, meaning security tools are less likely to flag them as a threat. The campaign has used ClickFix for initial access since February 2026 and has compromised at least 31 organizations across government, technology, and hospitality sectors. Command-and-control infrastructure runs over the Ethereum blockchain to resist traditional domain-based takedown efforts.
Restrict unsigned Node.js execution where it is not a documented business requirement. ClickFix has moved well past fake CAPTCHA pages.
 
Enforcement
Interpol’s Operation Jackal IV ran from November 2025 through June 2026, targeting networks linked to Black Axe, the West African criminal organization behind a significant share of global BEC fraud and romance scams. The operation netted 58 arrests across Argentina (17), South Africa (39), and Romania (11), spanning 22 participating nations. Romanian investigators found $166 million in stolen and laundered funds. Some sextortion victims targeted in the operation were as young as 14.
Black Axe playbooks are modular and survive enforcement. The arrests disrupt current infrastructure; the methodology continues.
🛠️ Tools & Tactics
 
 
Patch Now
Microsoft’s September 8 Patch Tuesday fixed 966 vulnerabilities, a new record for a single Patch Tuesday. Two of those, CVE-2026-81963 (Windows Update Stack elevation of privilege) and CVE-2026-85880 (Windows ALPC heap buffer overflow), are confirmed exploited in the wild and are now on CISA’s Known Exploited Vulnerabilities catalog. Federal agencies are under a September 22 deadline under BOD 26-04. For everyone else, both CVEs allow a local attacker to escalate to SYSTEM, which is how a contained post-initial-access breach becomes catastrophic.
Pull the September 8 Windows update now. These two CVEs first.
🧪 Strange Cyber
 
Strange but real
🚔 Qilin Ransomware Hacked the Federal Agency That Investigates Criminal Networks. Then Published the Files.
Intro
Qilin ransomware hit the Bureau of Alcohol, Tobacco, Firearms and Explosives. The ATF confirms it. The DOJ formally classified it a “major incident,” which requires mandatory notification to Congress.
What Happened
Qilin breached a standalone ATF system containing information on the agency’s active investigation targets. After the ATF declined to negotiate, the group published the files: phone extractions from criminal investigations, field office documents. The ATF says the system was isolated and shut down immediately after discovery.
Why It Matters
When investigation files go public, the harm goes beyond embarrassment. Witnesses, informants, and ongoing case strategies may now be visible to the networks those investigations were targeting, which can disrupt active law enforcement operations rather than just leaking data.
The Other Side
The ATF says the compromised system wasn’t connected to any other ATF infrastructure and that operational capability hasn’t been affected. No broader mission compromise has been confirmed.
 
👉 Takeaway
Law enforcement networks are now real ransomware targets with real leverage, not just for financial extraction, but for what publishing the seized files does to ongoing criminal cases.
TL;DR: Qilin hacked the ATF, published its investigation files, and the people under active federal investigation may now know what the ATF had on them.
Further reading: SecurityWeek

Smarter CRM. Less Busywork.

Disconnected data and tools make it harder to understand your customers. HubSpot's Agentic Customer Platform brings your data, teams, and tech stack together with AI built in to help your business work faster and create more personalized customer experiences.

Why HubSpot and what's new

  • Use AI powered tools to take action faster

  • Unify your data, teams, and tech stack in one place

  • Create one shared view of customer data

  • Connect teams around the same customer context

  • Bring your business tools into one place

Connect more of your business in one place and give every team a smarter way to work. Get set up quickly and start checking off your hardest tasks.