~/greenteam/nerd

Monday, September 21, 2026

Daily digest

Today's cybersecurity news is dominated by supply-chain attacks — malicious npm packages, booby-trapped Rust crate 'job interviews,' a North Korea-linked IT services breach, and an AI coding sandbox escape all point to escalating risk in developer tooling and third-party software.

cybersec BleepingComputer

Microsoft September Updates Break File History Backup Feature

Microsoft confirmed that the September 2026 security updates for Windows can cause the built-in File History backup feature to stop working on affected systems. The issue is under investigation, with no fix currently available beyond workarounds Microsoft has documented.

Why it matters: If File History is used anywhere in your Intune-managed Windows 11 fleet for endpoint backup, validate backup jobs post-patch before relying on them for recovery, especially given CMMC data-recovery/contingency planning requirements (CP family).

cybersec The Hacker News

Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors

SentinelOne attributed a breach of a small India-based IT services company to the North Korean threat actor Jade Sleet, which used Apple-related lures to target developers. The intrusion deployed previously undocumented FLATROOF and ROOFDECK backdoors as part of the group's ongoing campaign against software developers to gain downstream network access.

Why it matters: This is another nation-state campaign targeting IT service providers as a pivot point — a reminder to scrutinize third-party/MSP access into your environment under CMMC supply chain risk expectations.

cybersec BleepingComputer

Malicious npm Packages Evade Install-Script Defenses at Runtime

An ongoing npm malware campaign centered on the 'indexed-btree' package shows attackers hiding malicious code in normal runtime behavior rather than install scripts, bypassing common supply-chain scanning defenses. Researchers say this technique makes detection significantly harder for tools that only inspect install-time actions.

Why it matters: If any internal tooling, automation scripts, or self-hosted AI stack components pull npm dependencies, install-time scanning alone is no longer sufficient — runtime behavior monitoring should be part of your dependency vetting process.

cybersec The Register

Rustaceans Warned of Job Interviews With a Malicious Payload

Attackers are targeting Rust crate maintainers with fake company profiles and fabricated job interview processes, using booby-trapped recruitment materials to deliver malware. The campaign mirrors similar social-engineering supply-chain attacks previously seen against npm and PyPI maintainers.

cybersec BleepingComputer

Researchers Escape OpenAI Codex Sandbox to Run Commands on Host

Security researchers found two methods to break out of OpenAI's Codex sandbox, including one that allowed running commands on a developer's host machine even from the tool's most locked-down execution mode. OpenAI has patched both vulnerabilities.

Why it matters: Sandbox escapes in AI coding assistants are directly relevant if any self-hosted or cloud AI dev tooling is used in your environment — treat AI code-execution sandboxes as untrusted boundaries, not hard security controls.

cybersec SANS ISC

TerminalFix Campaign Uses PNG Steganography for Multistage Intrusion

Microsoft Security Research detailed a campaign dubbed TerminalFix that deploys a reverse tunnel through a multistage intrusion chain, using PNG image files with embedded steganographic payloads. SANS ISC obtained IOCs for the malicious PNGs from the researchers to aid detection.

cybersec Ars Technica Security

Undercover Google Analyst Infiltrated Supply-Chain Hacking Gang

Google's Threat Intelligence Group revealed it had a mole embedded inside the inner circle of TeamPCP, a threat actor group known for supply-chain hacking operations. The infiltration gave Google visibility into the group's tactics and planning over an extended period.

cybersec The Register

Google Confirms AI Agent Was Used to Hack a Partner, Kept It Quiet for Months

Google disclosed that one of its AI agents was misused after a partner made an internet access configuration error, resulting in unauthorized access to systems. Google reportedly sat on the disclosure for months, even after OpenAI had already disclosed a similar incident with its own AI agents.

Why it matters: As agentic AI tools get integrated into IT workflows, misconfigured internet/network access for these agents is emerging as a real attack vector — worth reviewing egress controls on any AI agents in your self-hosted stack.

cybersec The Hacker News

ClickFix Lures Deploy New ChainScript RAT Using Polygon Blockchain for C2 Rotation

Blackpoint researchers identified a previously undocumented remote access trojan called ChainScript, delivered via ClickFix-style social engineering lures disguised as Spotify, Zoom, and Microsoft Teams installers. The malware uses the Polygon blockchain to rotate its command-and-control infrastructure, making takedown more difficult.

Why it matters: ClickFix-style lures impersonating Teams/Zoom installers are a direct phishing risk to end users on your Intune-managed fleet — reinforce user awareness training and application allowlisting.

infrastructure The Register

VMware Quietly Walks Back Its SmartNIC Ambitions

VMware has scaled back its push for SmartNIC/DPU offload as a mainstream hyperscale hardware feature after failing to generate customer excitement. Some of the underlying technology may continue in limited form, but the broader strategy has been de-prioritized.

infrastructure The Register

Cambium Networks Set to Shut Down Its Cloud Management Portal

Cambium Networks is exiting the enterprise networking hardware business and will shut down its cloud-based device management portal. The company is urging customers to migrate to on-premises management software as soon as possible before the cloud service is retired.

Why it matters: If any Cambium networking gear is in use, plan migration to on-prem management now — losing centralized visibility into network devices could create both an operational gap and a compliance documentation gap for network configuration management controls.