Threat Alerts
Your place for the latest CyberProof cyber threat intelligence alerts and updates
Speak with an ExpertCozy Bear Uses AI to Autonomously Rebuild Malware and Evade Detection
In a notable evolution of AI-enabled cyber operations, a Russian state-linked espionage actor whose activity is consistent with Cozy Bear (Midnight Blizzard) has been observed using AI agents to automatically modify and rebuild malware in response to security detections. Rather than using AI only to assist with coding or reconnaissance, the actor configured AI-driven workflows to monitor whether deployed implants were detected and, when flagged, autonomously modify, recompile, and redeploy the malware, iterating until a variant successfully evaded detection. AI was also integrated across other stages of the operation, including reconnaissance, phishing infrastructure development, credential harvesting, persistence, C2, and data exfiltration. This represents a significant evolution in the operational use of AI, where malware can be rapidly regenerated in response to defensive detections, reducing the effectiveness of static indicators and increasing the importance of behavioral and TTP-based detection.
Microsoft Patches Two Actively Exploited Windows Zero-Days
Two actively exploited Windows zero-day vulnerabilities have been addressed as part of Microsoftβs September 2026 Patch Tuesday. The vulnerabilities, CVE-2026-85880 (CVSS 7.8) and CVE-2026-81963 (CVSS 7.8), are privilege escalation flaws that can allow attackers with existing access to elevate privileges to SYSTEM.
CVE-2026-85880 is a heap-based buffer overflow vulnerability affecting Windows Advanced Local Procedure Call (ALPC). An attacker capable of executing code within a low-privilege AppContainer can exploit the flaw to escape the sandbox and obtain elevated privileges without additional user interaction. CVE-2026-81963 affects the Windows Update Stack and results from improper link resolution, potentially allowing a local attacker to manipulate the update process and gain SYSTEM-level privileges. Both vulnerabilities have been observed under active exploitation, although details regarding the associated threat actors and attacks have not been disclosed.
The vulnerabilities were addressed as part of a record Patch Tuesday release covering 974 vulnerabilities across Windows, Office, SQL Server, Exchange, SharePoint, and other Microsoft products, with more than 110 rated Critical. Other high-severity vulnerabilities include multiple unauthenticated remote code execution flaws with CVSS scores of 9.8 affecting Windows Remote Desktop Services, Windows DNS Server, Windows DHCP Server, Windows Shell, and Windows Services for NFS, as well as critical vulnerabilities affecting SQL Server, Exchange Server, and SharePoint.
Actively Exploited Chrome V8 Zero-Day Enables Memory Corruption
An actively exploited zero-day vulnerability, tracked as CVE-2026-87491, has been addressed in Google Chrome. The vulnerability affects the V8 JavaScript and WebAssembly engine and has been confirmed to be exploited in the wild, making it the seventh Chrome zero-day observed under active exploitation this year.
Successful exploitation could potentially allow an attacker to trigger memory corruption through specially crafted web content, which may lead to arbitrary code execution within the browser context. Exploitation would typically require a user to visit or be redirected to a malicious webpage.
Critical SAP Vulnerabilities Enable Authentication Bypass and Remote Code Execution
Four critical vulnerabilities have been addressed as part of SAPβs September 2026 Security Patch Day, affecting SAP Kernel, NetWeaver, SAP Cloud Application Programming Model (CAP), and SAP GUI for Java. The vulnerabilities range from CVSS 9.0 to 10.0, with several allowing attacks without authentication.
The most severe, CVE-2026-44756 (CVSS 10.0), is a memory corruption vulnerability in SAP Extended Passport (EPP) processing, also referred to as OVERPASS. The flaw can be reached before authentication through multiple communication paths, including HTTP/S, SAP GUI, and RFC, and successful exploitation can result in arbitrary code execution with SAP-level operating system privileges.
CVE-2026-58240 (CVSS 9.8), known as S4GET, is a missing authentication check in the SAP NetWeaver Message Server. An unauthenticated attacker with network access could register a malicious component as a trusted application server and potentially execute commands within the SAP environment.
The remaining critical vulnerabilities include CVE-2026-76969 (CVSS 9.4), a credential disclosure vulnerability in multitenant applications using the SAP CAP sap/cds-mtxs library that could allow unauthenticated access to sensitive credentials and modification or deletion of tenant data. CVE-2026-66768 (CVSS 9.0) is an improper access control vulnerability in SAP GUI for Java that could allow a low-privileged attacker operating a malicious backend to execute arbitrary commands on a victim system, although user interaction is required.
Ivanti Patches Critical Vulnerabilities Across Enterprise Products
Ivanti has released security updates addressing multiple critical and high-severity vulnerabilities across three enterprise products, affecting solutions used for IT service management, endpoint management and network security. The IT service management platform received the largest set of fixes, with eight vulnerabilities, including six critical flaws capable of enabling remote code execution. Several involve missing authorization and deserialization of untrusted data with severity ratings reaching CVSS 9.9. Two of the critical vulnerabilities can be exploited without authentication, while the remaining deserialization flaws require an authenticated user.
The network security gateway product was also patched for a high-severity authentication bypass vulnerability, CVE-2026-83527 which allows a remote unauthenticated attacker to obtain administrative privileges and potentially gain full control of the affected system. The mobile endpoint management product received a fix for another high-severity authentication bypass, CVE-2026-18851, although exploitation requires prior authentication. No active exploitation has been observed for the vulnerabilities at the time of disclosure but organizations using affected Ivanti products should prioritize applying the available security updates.
MacSync Stealer Uses ClickFix Lures to Target macOS Users
Researchers have identified ongoing campaigns distributing MacSync, a macOS information stealer and remote-access stager offered under a Malware-as-a-Service (MaaS) model. MacSync is primarily delivered through ClickFix social engineering, malvertising, SEO poisoning, compromised websites, and fake software installers. Victims are commonly presented with fake software errors, CAPTCHA verification prompts, or application installation instructions that convince them to copy and execute malicious commands in the macOS Terminal. Campaigns have impersonated widely used applications and services including Zoom, Google Meet, ChatGPT, Claude AI, Docker, Notion, and Cursor.
Following execution, MacSync deploys lightweight 64-bit Mach-O stagers designed to reduce its footprint and evade security controls such as Gatekeeper, XProtect, and EDR solutions. The malware can retrieve and execute AppleScript directly in memory, collect browser data, macOS Keychain information, session cookies, SSH keys, credentials and other sensitive information, before exfiltrating the collected data to attacker-controlled infrastructure. Some variants also deploy a secondary RAT and establish persistence through malicious LaunchAgent entries. MacSync incorporates string obfuscation, background process execution and artifact cleanup to complicate detection and analysis.





