We've got one word for it, and it's usually the wrong one
This week's Threat Source newsletter highlights a complex security issue stemming from the cybersecurity industry's struggle to adequately address the psychological toll of its work. Cisco Talos is investigating a sophisticated WebDAV infection chain attributed to a Russian threat actor, leveraging a Google Visualization API for command and control to deliver the Amatera stealer and secondary payloads like ZigCryptoStealer and NetSupport Manager. The campaign is opportunistic and broad-based, aiming to steal cryptocurrency and credentials. Additionally, the newsletter details a zero-day exploit for Microsoft Defender, a North Korean espionage toolkit targeting automotive and media organizations, and a phishing campaign utilizing Google redirects. Finally, it covers a campaign weaponizing greed to trick amateur cybercriminals into compromising their systems.
Welcome to this week’s edition of the Threat Source newsletter.
This week’s focus is on the often-overlooked mental health challenges within the cybersecurity industry. The newsletter begins by noting that the industry struggles to adequately address the psychological impact of its work, leading to a lack of appropriate language and support.
Cisco Talos is investigating a complex WebDAV infection chain attributed to a Russian threat actor tracked as UAT-10820. The campaign leverages a Google Visualization API for command and control (C2) to deliver the Amatera stealer alongside secondary payloads like ZigCryptoStealer and NetSupport Manager. Despite the high-profile initial victim, Talos assesses with moderate confidence that this is an opportunistic, broad-based cryptocurrency and credential-stealing operation rather than a highly targeted attack.
Threat actors are getting increasingly creative with their delivery mechanisms and evasion tactics. By abusing legitimate infrastructure like the BNB Smart Chain for bulletproof hosting and leveraging fake CAPTCHA prompts, attackers can easily bypass traditional web filters. The secondary payloads pack a serious punch, including a vulnerable driver to terminate EDR software and the deployment of unauthorized remote access tools, giving attackers deep, persistent control over infected systems.
Alongside this, the newsletter details a zero-day exploit for Microsoft Defender named ‘ShieldCrash’ that grants SYSTEM access, a North Korean espionage toolkit targeting automotive and media organizations in South Korea, and a phishing campaign utilizing multi-hop Google redirects to bypass security tools. Finally, it covers a campaign weaponizing greed to trick amateur cybercriminals into compromising their systems.
**Top security headlines of the week:**
- **New Microsoft Defender ‘ShieldCrash’ zero-day grants SYSTEM access:** An anonymous security researcher, Nightmare Eclipse, has released a new Microsoft Defender zero-day exploit named “ShieldCrash” right after Microsoft rolled out its September 2026 Patch Tuesday security updates.
- **North Korean hackers deploy new Linux espionage toolkit:** The stealthy toolkit embeds a backdoor in HAProxy and targets automotive and media organizations in South Korea for long-term surveillance. The toolkit supports remote command execution, credential harvesting, and script injection into web traffic.
- **Attackers use multi-hop Google redirects for phishing campaign:** What sets this campaign apart is that in order to bypass gateways, email filters, and other security tools, the link relies on a chain of redirects across Google domains, intending for link inspectors to see multiple Google domains and let the URL through.
- **OpenAI agents took over Wiki site before Hugging Face attack:** A team of independent researchers revealed the parallel incident on Sept. 4, which was first reported by Reuters, affecting a largely defunct German language wiki for programmers called “DeutschesSoftwareEntwickler wiki.”
**Patch Tuesday for September 2026:** Microsoft has released its monthly security update for September 2026, which includes 973 vulnerabilities affecting a range of products, including 113 that Microsoft marked as “critical.”
**Active exploitation of Cisco Secure Firewall Management Center vulnerabilities:** Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco’s Secure Firewall Management Center (FMC) Software: CVE-2026-20079 and CVE-2026-20316. Customers are strongly advised to apply hotfixes for affected software versions already released by Cisco.
**ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2:** Cisco Talos is tracking a cryptocurrency-stealing campaign that abuses the Google Visualization API for command and control (C2), retrieving obfuscated JavaScript from a publicly published Google Sheets document and injecting it into the victim’s browser session.
**Browser betrayal: When your tabs turn against you:** Security Engineer Sean Gallagher joins Amy to break down a scam where threat actors are weaponizing greed to turn amateur cybercriminals against themselves. While this current operation mostly targets the amateur dark-web circuit, the underlying use of the Google Visualization API as a command-and-control channel is a red flag for the future of web security.
**Upcoming events where you can find Talos:**
- .conf26 (Sept. 14 – 17) Denver, CO
- CYBR.SEC.CON. (Sept. 15 – 16) Houston, TX
- LABSCon (Sept. 16 – 19) Scottsdale, AZ
- VB (Oct. 14 – 16) Seville, Spain
- CAMLIS (Oct. 21 – 23) Arlington, VA
**Most prevalent malware files from Talos telemetry over the past week:**
- SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507
- MD5: 2915b3f8b703eb744fc54c81f4a9c67f
- Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507
Example Filename: VID001.exe Detection Name: W32.9F1F11A708-100.SBX.TG**
- SHA256: 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59
- MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a
- Talos Rep: https://talosintelligence.com/talos_file_reputation?s=90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59
Example Filename: tmp00055df5.dll Detection Name: Auto.90B145.282358.in02
- SHA256: c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2
- MD5: 38de5b216c33833af710e88f7f64fc98
- Talos Rep: https://talosintelligence.com/talos_file_reputation?s=c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2
Example Filename: SECOH-QAD.exe Detection Name: Win.Dropper.Procpatcher::1201
- SHA256: 5bb86c1cd08fe5e1516cba35c85fc03e503bd1b5469113ffa1f1b9e10897f811
- MD5: f3e82419a43220a7a222fc01b7607adc
- Talos Rep: https://talosintelligence.com/talos_file_reputation?s=5bb86c1cd08fe5e1516cba35c85fc03e503bd1b5469113ffa1f1b9e10897f811
Example Filename: 5bb86c1cd08fe5e1516cba35c85fc03e503bd1b5469113ffa1f1b9e10897f811.exe Detection Name: Win.Dropper.Procpatcher::1201
