Canadian Cyber Security Journal
SOCIAL:
Filed under: News

Cybersecurity Daily Brief — Friday, September 25, 2026

Here are today’s top cybersecurity stories for Friday, September 25, 2026.

North Korea Suspected in $351.6 Million Bitget Crypto Exchange Hack
An attacker compromised a backend system inside crypto exchange Bitget’s wallet infrastructure on September 24 and authorized fraudulent transfers from hot wallets, moving roughly $351.6 million in Ethereum, XRP, BNB, AVAX, USDT, and USDC across several blockchains. Bitget CEO Gracy Chen said IP behavior and on-chain analysis point to patterns consistent with known North Korean hacking groups, though the company named no specific threat actor. Cold storage stayed untouched, and several blockchain foundations froze wallet addresses tied to the attacker. SecurityWeek

Infostealer Malware Exposes Credentials at 1,787 US Water Utilities
A SpyCloud study of roughly 10,000 EPA-registered water and wastewater organizations found active infostealer exposure at 1,787 of them, with 258 organizations showing stolen credentials tied to operational technology or remote-access systems such as TeamViewer. One infected device at a smart meter provider held saved logins for about 167 separate utility clients, a pattern researchers call cascading supply chain exposure. Infostealer logs also carry session cookies and autofill data, letting attackers bypass multi-factor authentication entirely. CyberScoop

Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories
An attacker took over an active AI coding assistant session at an unnamed software provider and used it to install an infostealer through a poisoned PyPI package, stealing GitHub OAuth tokens and source code from roughly 100 internal repositories. The attacker also poisoned a package inside the company’s own namespace, infecting a second employee who downloaded it. Mandiant recommends verifying AI-suggested dependencies against checksums, restricting secrets access from coding extensions, and routing dependency traffic through controlled internal repositories. The Hacker News

Cloudflare Fixes Flaw Letting Containers Read Other Customers’ Leftover Disk Data
Cloudflare Containers and Sandboxes used Linux thin provisioning with disk wiping disabled, so deleted containers returned their storage blocks to a shared pool without clearing them first. A new container was then able to read residual directory structures, database pages, and credential files left behind by a previous customer’s container, though Cloudflare said an attacker had no way to choose whose data they received. The company re-enabled block wiping and retired every running container disk by September 19, and found no evidence of exploitation outside authorized research. The Hacker News

ShinyHunters Hacks Clop Ransomware Gang’s Own Leak Site
The ShinyHunters extortion group hacked into the Tor-based leak site run by the Clop ransomware gang, stealing server logs and cryptographic keys. ShinyHunters demanded an eight-figure ransom and a public apology from Clop, in what researchers describe as retaliation tied to a prior feud between the two groups. The incident offers a rare look at conflict among ransomware and extortion operators themselves. SecurityWeek

Poisoned MemOS Packages Deliver Go-Based Malware Targeting API Keys
Attackers published tampered versions of MemOS packages containing a Go-based malware variant researchers named sckit. The implant activates when a developer imports the poisoned library and searches infected systems for API keys tied to GitHub, AWS, Hugging Face, and other developer services. The campaign adds to a run of supply chain attacks aimed squarely at AI and machine learning development pipelines. SecurityWeek

Elementor WordPress Plugin Flaw Lets Attackers Create Admin Accounts
Security firm Patchstack found a cross-site request forgery flaw in Elementor versions 4.3.0 and 4.3.1, affecting roughly 2 million websites. The bug lets an attacker trick a logged-in administrator into opening a malicious link, triggering an unauthorized REST API call creating a new administrator account on the site. Elementor released version 4.3.2 on September 24, two days after the report. BleepingComputer

SalesBleed Research Shows Salesforce Agentforce Flaws Enable Slack Phishing
Researchers at Zenity found a set of vulnerabilities, dubbed SalesBleed, in Salesforce Agentforce, letting an attacker inject malicious prompts through public Web-to-lead forms and direct an AI agent to send phishing messages inside Slack under forged internal attribution. Salesforce patched the issue by requiring user confirmation before Agentforce sends Slack messages and adopting spec-conformant URL parsing in place of regex matching. The findings build on earlier Web-to-lead exploitation research Noma Security published a year earlier. Dark Reading

Rydox Marketplace Administrator Pleads Guilty, Faces Up to 20 Years
Kosovar national Ardit Kutleshi pleaded guilty to aggravated identity theft and money laundering conspiracy for running Rydox, a marketplace selling stolen credentials, credit card data, phishing kits, and stealer logs to roughly 18,000 registered users between 2016 and its December 2024 seizure. Sellers completed more than 7,600 transactions alongside over 321,000 other illicit listings, and investigators recovered about $225,000 in cryptocurrency when they seized the domain and servers. Two co-conspirators face related charges, and Kutleshi faces sentencing on February 9, 2027. SecurityWeek

Critical TDengine Flaw Threatens Industrial Telemetry Systems
CVE-2026-42542 is a pre-authentication integer underflow in the TDengine time-series database, letting an unauthenticated attacker crash a server with a single malformed packet. The affected database sees wide use in industrial telemetry across the energy and utilities sectors, where a denial-of-service condition disrupts monitoring rather than exposes data directly. Operators running TDengine should confirm patch status and restrict network exposure to the service where possible. SecurityWeek

Stay tuned for today’s in-depth analysis posts.

Enjoy this article? Don’t forget to share.