W1RETAP Intel Report — 2026-09-19
W1RETAP INTEL REPORT
September 19, 2026
================================================================
SEVERITY: 6/10 — ELEVATED
JUSTIFICATION: A mass supply chain compromise hit 100,000+ websites, a CVSS 10.0 GitLab flaw was exploited within 24 hours of disclosure, and multiple multi-million-record breaches surfaced this week, but no single event this cycle reached active nationwide critical-infrastructure disruption.
TOP STORY:
A supply chain attack against email/marketing platform Brevo briefly turned its own infrastructure into a malware delivery channel for more than 100,000 customer websites. Attackers stole a Cloudflare API key tied to Brevo's account and used it to stand up a malicious Cloudflare Worker that altered content at the CDN edge for roughly five and a half hours on September 14. The worker had two payloads depending on the visitor: signed-in WordPress admins were served a script attempting to silently install a plugin (assessed as likely a backdoor), while ordinary visitors were shown a fake Cloudflare human-verification page followed by ClickFix-style instructions tricking them into running a malicious command on Windows. Affected surfaces included brevo.com, sendinblue.com, onboarding.brevo.com, sibforms.com, and the Brevo forms, Conversations widget, and SDK loader scripts embedded across customer sites. This is a reminder that CDN-edge and API-key compromise remain a high-leverage way to weaponize trusted third-party scripts at scale without touching a single customer's own code.
BREACHES & INCIDENTS:
CenterPoint Energy disclosed a breach exposing roughly 6.7 million customer records (reported September 16). An Argentine insurance company had approximately 3.66 million lines of customer data leaked, also disclosed September 16. Energynet in Serbia reported a customer-database breach affecting 56,909 customers on September 17. Separately, a Gyazo data breach and a wave of ChatGPT-billing phishing emails targeting OpenAI account credentials were both reported in the last 24-48 hours. These sit alongside an already active 2026 breach year that includes the DentaQuest healthcare breach (15 million people), underscoring continued heavy targeting of energy, insurance, and healthcare data.
VULNERABILITIES & EXPLOITS:
The standout this week is CVE-2026-85706, a CVSS 10.0 unauthenticated path traversal flaw in GitLab CE/EE's repository commits API that lets an attacker read arbitrary files off the server with a single unauthenticated HTTP request. GitLab patched it September 10; in-the-wild exploitation began within 24 hours, and CISA added it to the Known Exploited Vulnerabilities (KEV) catalog on September 11. Attackers have moved from probing to actively dumping config files, secrets, and SSH configurations from vulnerable instances (affected versions: 18.7 before 19.1.8, 19.2 before 19.2.6, 19.3 before 19.3.2). Also notable: Google patched an actively exploited Chrome V8 zero-day (CVE-2026-85046, CVSS 8.8), added to KEV September 4; September Patch Tuesday shipped a record CVE count and included two already-exploited Windows elevation-of-privilege zero-days (CVE-2026-81963, Windows Update Stack; CVE-2026-85880, Windows ALPC); CISA confirmed 9 newly exploited vulnerabilities added to KEV in the past 7 days as of September 18 (following 15 the week prior); ransomware crews are actively riding a critical VMware vCenter flaw patched in July and a WatchGuard Firebox vulnerability flagged since December; and three separate threat clusters (criminal and state-linked) are exploiting two recently patched Cisco Secure Firewall Management Center flaws. On the web side, a new "Click2Shell" exploit chain can turn a single malicious link into remote code execution on vulnerable WordPress sites.
TOOLS & TECH:
A new attack technique called "BragJack" lets a malicious browser extension hijack the trusted communication channels AI browser assistants use inside Chrome, Edge, and Opera — a fresh angle on abusing the AI-assistant trust boundary rather than the browser itself. On mobile, a new Android malware family dubbed RatHat includes an AI-powered subsystem that helps operators navigate compromised devices remotely, and a separate strain called Mantax Otax combines ransomware and spyware/harassment capabilities in one payload. On the defensive/offensive tooling side, Kali Linux's 2026.2 release added tools including arsenal-ng, hydra-gtk, legba, shell-gpt, and tailscale, building on 2026.1's additions of AdaptixC2 (post-exploitation/adversarial emulation framework) and MetasploitMCP (an MCP server built for the Metasploit framework) — both signs that AI-agent tooling is now migrating directly into the standard pentest stack. Separately, the NightmareStresser DDoS-for-hire service was disrupted.
U.S. GOVERNMENT CYBER MOVES:
NSA published new "Best Practices for Cyber Hygiene" guidance warning that adversaries are using AI to automate each stage of the intrusion lifecycle, and is reportedly planning a major internal reorganization into five mission centers covering AI, China, cybersecurity, combat support, and global intelligence — with its Tailored Access Operations hacking unit expected to move under the global intelligence arm and gain resources once the federal budget resets. CISA released three new ICS advisories (ICSA-26-260-01/02/03) on September 17 plus an advisory on CareCam Pro IP cameras, continuing steady ICS-focused output. CISA also confirmed it will sunset its long-running weekly Vulnerability Bulletin on September 28 as part of a shift from severity-based to risk-based vulnerability management — a notable process change for anyone who relies on that bulletin for patch triage. Separately, DOJ and the FBI announced the seizure of platforms operated by China state-sponsored hackers used to target U.S. critical infrastructure.
TRENDS TO WATCH:
AI is now cutting both ways in this fight: attackers are embedding AI directly into malware (RatHat) and targeting the trust relationship users place in AI browser assistants (BragJack), while NSA is simultaneously pushing hygiene guidance aimed at AI-automated intrusion chains. Supply-chain compromise continues to favor stolen credentials and CDN/API-key abuse over traditional malicious-package injection, as seen in the Brevo incident — a lower-noise, higher-blast-radius technique worth tracking. CISA's move away from a static severity-based bulletin toward continuous risk-based vulnerability management also signals where vulnerability-prioritization practices industry-wide are likely headed next.
--
Report window: news from approximately September 17-19, 2026. Compiled via automated web search of Krebs on Security, BleepingComputer, The Hacker News, Dark Reading, CISA.gov, The Record, SecurityWeek, and related sources.