CyberNews: 09/09/2026 Edition

Published by Dunateo on 2026-09-09

Today’s roundup

  • Fortinet Warns of Critical RCE in FortiClient EMS, Urges Immediate Patching
  • Microsoft Warns of Phishing Attacks Using Open Redirects in Google and Facebook
  • New Akira Ransomware Attacks Target VMware ESXi Servers, Exfiltrate Data
  • DarkGate Malware Exploits CVE-2024-21338 in Windows Defender SmartScreen
  • Critical Vulnerability in ConnectWise ScreenConnect Actively Exploited (CVE-2024-46805)
  • Russia-Linked APT28 (Fancy Bear) Exploits Old Microsoft Outlook Vulnerability
  • New Lazarus Group Campaign Targets IT Companies in South Korea
  • US Treasury Sanctions Sinbad Mixer for Aiding North Korean Cybercriminals
  • Summary

    Fortinet has issued a critical warning regarding a remote code execution vulnerability, CVE-2023-48788, affecting its FortiClient Endpoint Management Server (EMS). The flaw, rated 9.3 out of 10, allows an unauthenticated attacker to execute arbitrary code with SYSTEM privileges via a specially crafted request. Immediate patching is urged for all affected versions.

    Microsoft has reported a new wave of advanced phishing attacks targeting Microsoft 365 users, utilizing open redirect vulnerabilities found in legitimate services like Google and Facebook. Threat actors craft sophisticated emails that bypass security filters by pointing to trusted domains before redirecting victims to malicious credential-harvesting pages.

    The Akira ransomware group has expanded its attack vectors to target VMware ESXi servers, a significant shift from its previous focus on Windows systems. The group is leveraging known vulnerabilities in ESXi to encrypt virtual machines and exfiltrate data, posing a severe threat to organizations relying on VMware virtualization.

    DarkGate malware is now actively exploiting a critical vulnerability, CVE-2024-21338, in Windows Defender SmartScreen. This zero-day exploit allows attackers to bypass security measures and deliver malware, impacting unpatched Windows systems and highlighting the continuous evolution of malware delivery techniques.

    A critical authentication bypass vulnerability, CVE-2024-46805, has been discovered and is under active exploitation in ConnectWise ScreenConnect, a widely used remote desktop solution. The flaw allows unauthenticated attackers to gain administrative access, potentially leading to widespread network compromise. Patches are immediately available.

    The Russia-linked advanced persistent threat group APT28, also known as Fancy Bear, has been observed exploiting an old, patched Microsoft Outlook vulnerability, CVE-2023-23397. This elevation of privilege flaw allows attackers to steal NTLM hashes through specially crafted calendar invitations, demonstrating ongoing exploitation of previously disclosed vulnerabilities.

    North Korea's state-sponsored Lazarus Group has initiated a new campaign targeting IT companies in South Korea. The attacks aim to infiltrate networks and exfiltrate sensitive data, employing social engineering and sophisticated malware tailored for espionage and financial gain within the region.

    The US Department of the Treasury has sanctioned the virtual currency mixer Sinbad for its role in processing illicit funds, particularly for North Korean cybercriminals, including the Lazarus Group. The mixer facilitated transactions worth millions of dollars, aiding in money laundering activities for financially motivated state-sponsored operations.

    Want to dig deeper?

    Vulnerabilities

    CVE-2024-21338 High
    CVE-2024-46805 Medium
    CVE-2023-48788 High
    CVE-2023-23397 High

    Cyber Groups

    Akira GOLD SAHARA, PUNK SPIDER, Howling Scorpius
    APT28 IRON TWILIGHT, SNAKEMACKEREL, Swallowtail, Group 74, Sednit, Sofacy, Pawn Storm, Fancy Bear, STRONTIUM, Tsar Team, Threat Group-4127, TG-4127, Forest Blizzard, FROZENLAKE, GruesomeLarch
    Lazarus Group Labyrinth Chollima, HIDDEN COBRA, Guardians of Peace, ZINC, NICKEL ACADEMY, Diamond Sleet

    Malware Families

    Akira REDBIKE