TL;DR for CISOs: A fake LastPass Authenticator download installs a kernel driver signed through Microsoft's own hardware compatibility program that hunts 145 named antivirus and EDR processes before an infostealer empties the browser, BigCommerce told merchants that stolen credentials for a third-party app named Ribon were used to inject scripts into storefronts and to reach shopper records, and four governments put numbers to the North Korean fake-recruiter campaign at 30,000 devices and $10.71 million in stolen cryptocurrency.
- A valid Microsoft signature is not a safety verdict. The driver in today's lead story passed attestation in March 2023 and was never on the vulnerable driver blocklist, so every control you own that trusts a signature chain passed this file through. Assume your blocklist is a floor, not a ceiling, and ask whether you enforce an allowlist for kernel drivers at all.
- Your third-party app inventory is an access inventory. One compromised application key at Ribon reached customer records through the platform's own interfaces, and the app was installed across hundreds of stores. The question for your team is not which vendors you use, but which vendor credentials can read your customer data through an API today, and who would notice if one of them started reading it at volume.
- Recruiting is now an initial access path with a government-issued number attached. Thirty thousand devices and more than 7,000 drained wallets came from developers who thought they were taking a coding test. If your engineers keep source code and cloud credentials on machines they also job-hunt from, that is an exposure your access reviews will never surface.
Lead story: a Microsoft-signed driver targets 145 security tools, then a stealer takes everything in the browser
CRITICAL · ACTIVE CAMPAIGNReported by: LastPass and Delphos Labs, joint report published September 17, 2026
Driver: Alinubx.sys, written to disk as nvfsflt64.sys, registered as the service NvFsFilter
Signature: Microsoft Windows Hardware Compatibility Publisher chain, signing date March 2023
Kill list: 145 hardcoded antivirus and EDR process names, terminated from kernel mode
Stealer: Rapuncel, previously undocumented, targets 25 browsers and 30 cryptocurrency wallets
Delivery: search-optimized fake GitHub pages impersonating at least 40 brands
Victim count: not disclosed; the report gives no figure
LastPass status: LastPass says its own systems, services and customer vaults were not touched
What happened
Someone searching for the LastPass Authenticator app finds a GitHub page that ranks well and looks like a product page. It is not one. Clicking download moves the visitor through a chain of GitHub pages to an attacker-controlled server, which hands back a ZIP archive padded with junk files so that scanners with a size limit skip it. The two archives the researchers examined were 148 MB and 127.9 MB. LastPass and Delphos Labs published the details on September 17 and say the same server was hosting impersonation pages for at least 40 brands.
Inside the archive is a renamed copy of a real Microsoft debugging tool, vsdbg.exe, sitting next to a malicious vsdbg.dll. Windows loads the attacker's library from the same folder, the loader tries three routes to administrator, reaches SYSTEM, and installs a kernel driver as a service. The driver is named Alinubx.sys, written to disk as nvfsflt64.sys so it reads as an NVIDIA component, and registered under the service name NvFsFilter.
The driver carries a hardcoded list of 145 antivirus and EDR process names and terminates each one it finds. It does this from the kernel, underneath the layer where those tools run, so they cannot see or block the kill. According to LastPass, the driver calls ObOpenObjectByPointer with AccessMode set to KernelMode, which skips the user-mode access check at handle-open time and lets it defeat Protected Process Light, the protection many endpoint products rely on to survive an attacker who already has administrator rights.
With the security stack down, the Rapuncel infostealer collects saved credentials from 25 browsers, data from 30 cryptocurrency wallets, Discord, Steam and Telegram session credentials, the contents of Windows Credential Manager, files whose names contain password, seed, wallet or recovery, screenshots from every connected monitor, and system details. For Chrome and Edge, which use app-bound encryption to stop exactly this, the stealer injects a helper DLL into the browser and asks the browser's own elevation service to decrypt the data. Everything is compressed and pushed to an external endpoint over raw TCP. The driver and stealer both persist as services, so tools that come back after a reboot are killed again before the stealer runs.
The part that should hold a CISO's attention is the provenance. The driver is a renamed copy of CcProtect.sys, a component of a Chinese disk-encryption product called CnCrypt that is already cataloged on LOLDrivers as a process killer with public proof-of-concept code. Same product name, same version, same submitter; only the file name and description changed. That rename dropped detections from 7 of roughly 70 VirusTotal engines in August to zero. Delphos checked Microsoft's vulnerable driver blocklist on August 20 and found neither the renamed file nor the known original on it. Delphos reported the driver to Microsoft on August 19. Microsoft replied that the behavior does not meet its definition of a security vulnerability, because the driver is not a Microsoft component, and pointed the researchers to the separate channel that considers drivers for the blocklist. As of the September 17 report, the driver was still not listed.
Evidence
Verified against two independent sources:
1. The Hacker News, "Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR," September 21, 2026
2. BleepingComputer, "Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer," September 18, 2026
What this means for your team
Most endpoint programs treat Microsoft's vulnerable driver blocklist as the control that handles this class of attack. This campaign shows what that control actually is: a list of file hashes. Recompile or rename the file and the hash changes, and the list does not carry it. The original driver here was never on the blocklist either, so the rename was not even the thing that got it past. It simply was never blocked.
That leaves a gap your architecture diagram probably does not show. If any attacker who reaches administrator can load a kernel driver of their choosing, then administrator and kernel are the same privilege level in your environment, and every detection you bought sits inside the blast radius. The teams that survive this pattern are the ones enforcing a driver allowlist through application control, not the ones subscribing to a longer blocklist.
The second point is about attribution of trust. Signing attestation tells you a driver passed through a pipeline. It does not tell you what the driver does. Any control logic in your fleet that reads "signed by a trusted publisher, therefore permit" is making a claim the signature does not support. That includes tooling decisions your endpoint team made years ago and has not revisited.
Third, note the delivery path. This did not arrive by email. It arrived because a developer or an administrator searched for a legitimate security tool and clicked the top result on a platform your organization almost certainly allows. Software acquisition by search is a real acquisition channel in most enterprises, and it is usually ungoverned.
- Hunt now for the published indicators across your Windows estate: a service named NvFsFilter, a driver at C:\Windows\System32\drivers\nvfsflt64.sys, any driver whose signing details name Henan Dafeng Software or contain CnCrypt, and the device path \\.\Alinubx. Pair that with a behavioral rule for any driver load followed within minutes by security process terminations, because the file name will change.
- Ask your endpoint team one question this week and require a written answer: can a local administrator on a standard build load an arbitrary signed kernel driver? If the answer is yes, put driver allowlisting through application control on the roadmap with a date, and treat the blocklist as an interim measure.
- Instrument the absence of telemetry. An endpoint that stops reporting is the signal this attack produces, and most SOCs alert on bad events rather than on silence. Set a detection for agent heartbeat loss on a managed asset and route it to an analyst, not to an asset-hygiene report.
- Treat any machine that ran this payload as a kernel-level compromise. Rotate every credential that touched it from a separate clean device, including browser-stored credentials and anything in Windows Credential Manager, and rebuild rather than clean, since the driver reloads and re-kills tooling on every boot.
BigCommerce merchants told shopper data was reached through a stolen third-party app key
HIGH · THIRD-PARTY BREACHPlatform: BigCommerce, which supports over 1,200 third-party applications and integrations
Compromised apps: Ribon and Ribon 1.5, owned and operated by Be A Part Of, a Fastr company
Access window: September 13 to September 17, 2026
Confirmed: BigCommerce confirmed the credential compromise on September 17 and removed the apps
Data exposed at one named merchant: full names, email addresses, phone numbers, shipping postal addresses
Not exposed: account passwords and payment card data, which BigCommerce says it stores separately
Regulator: Master of Malt reported the incident to the UK Information Commissioner's Office
What happened
BigCommerce confirmed on September 17 that credentials belonging to two third-party applications, Ribon and Ribon 1.5, had been compromised and used to inject malicious scripts into merchant storefronts. The company told BleepingComputer that it uninstalled the application from affected stores to revoke the attacker's access, notified those merchants directly, and is supplying log data to the developer's investigation. BigCommerce says its own platform and systems were not breached, and that account passwords and payment card information sit in separate storage that was not exposed.
UK spirits retailer Master of Malt is one of the merchants that received the notification. It says the attacker obtained a BigCommerce application key held by Ribon and used it to read customer data held inside BigCommerce, and that the exposed fields were full names, email addresses, phone numbers and shipping postal addresses. The retailer reported the incident to the UK Information Commissioner's Office and has said the impact may extend well beyond its own customers, potentially to hundreds of other stores, because Ribon was installed widely. It also said it will press BigCommerce for more granular API authorization controls, arguing a single compromised application credential should not be able to reach customer data at that scale.
BleepingComputer notes the parallel with a 2024 incident where attackers compromised the third-party FreshClick BigCommerce app and injected skimming code into a retailer's store. The difference matters. That earlier case captured payment details as shoppers typed them at checkout. This one used a stolen application key to read customer records that were already stored, through the platform's own interfaces. A law firm has begun seeking claimants linked to the incident, which is a claim about litigation interest rather than a finding about scope.
Evidence
Verified against two independent sources:
1. BleepingComputer, "BigCommerce alerts merchants of data breach linked to Ribon apps," September 21, 2026
2. Cyber Press, "Hackers Abuse Third-Party BigCommerce App to Steal Master of Malt Customer Data," September 22, 2026
What this means for your team
This is a multi-tenant failure, not a merchant failure. Every store that installed Ribon inherited the security of Ribon's credential handling, and none of them could see it. Master of Malt says the attack was not aimed at the retailer at all. The retailer was simply downstream of a credential it did not hold and could not rotate.
The structural lesson applies well outside retail. Marketplace and app-store integrations are usually approved once, by a business owner, on commercial grounds, and then hold broad read access to customer records forever. Your vendor risk process almost certainly assessed Ribon's questionnaire and not Ribon's token scope. Those are different risks, and only one of them shows up in a breach.
There is also a detection gap worth naming. Reads through a legitimate API with a legitimate key look like normal integration traffic. Four days of unauthorized access ended when BigCommerce confirmed the compromise and pulled the app, not because a merchant spotted anomalous read volume. If your SaaS platforms can show you per-integration data access rates, someone should be looking at them.
- Pull the list of installed third-party apps on every customer-facing SaaS platform you run, with the data scopes each one holds, and put it in front of the accountable business owner. Remove anything nobody can name a current use for.
- Set an expiry and a rotation owner for every integration credential that reads customer data. A key with no expiry and no owner is the exact asset that failed here.
- Ask each platform vendor two questions in writing: can you alert us on abnormal read volume by a single integration, and can you scope an app's access to fields rather than to the whole customer record? File the answers with the contract.
- If you operate an online storefront, check whether Ribon or Ribon 1.5 was installed, review storefront scripts for unexplained injections, and prepare notification language now rather than after a regulator asks.
Four governments put a number on the North Korean fake-recruiter campaign: 30,000 devices, $10.71 million
HIGH · NATION-STATE ADVISORYSource: joint cybersecurity advisory from agencies in Japan, the United States, Australia and Germany
Scale: at least 30,000 devices compromised across more than 100 countries
Wallets: funds or account credentials taken from over 7,000 cryptocurrency wallets
Losses: at least $10.71 million in cryptocurrency
Targets: individual web designers, engineers, and cryptocurrency, blockchain and Web3 specialists
Running since: at least 2022, first documented by Palo Alto Networks Unit 42
Enforcement: a laptop farm operated by a facilitator in Japan has been identified and dismantled
What happened
The campaign known as Contagious Interview now has official figures attached. A joint advisory from Japanese, US, Australian and German agencies puts it at a minimum of 30,000 compromised devices in more than 100 countries, more than 7,000 cryptocurrency wallets drained of funds or credentials, and at least $10.71 million taken. The same activity is tracked across the industry under a long list of names including DeceptiveDevelopment, Famous Chollima, PurpleBravo, UNC5342 and WaterPlum.
The method has not changed since 2022. Operators pose as recruiters, approach developers on social platforms including LinkedIn, build rapport, then send a coding assessment that starts a multi-stage infection chain. The malware families involved include BeaverTail, InvisibleFerret, FlexibleFerret, GolangGhost, PylangGhost, OtterCookie, RATatouille, OtterCandy and StoatWaffle, with remote access trojans following on for persistence and exfiltration.
The advisory is explicit that individual theft is not the endpoint. The agencies state that successful infections give the operators a route into the organizations employing the targeted developers, enabling espionage, intellectual property theft and lateral movement, and that stolen identity images are reused by North Korean IT workers to impersonate victims. Separately, Silent Push reported a North Korean IT worker recruiting proxies through a Discord server, offering people in the US, EU and Latin America $3,000 to $5,000 to act as the face and legal identity on job applications, with an offer to remotely complete live coding challenges. Both agencies and researchers describe the IT worker scheme and this campaign as closely connected; the specific organizational attribution in the advisory is presented as an assessment, not a confirmed fact.
Evidence
Verified against two independent sources:
1. The Hacker News, "Contagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in Crypto," September 21, 2026
2. BleepingComputer, "North Korean WaterPlum hackers infected 30,000 devices worldwide," September 19, 2026
What this means for your team
Security awareness programs are built around messages that arrive at work. This campaign arrives during a job search, on a personal device, through a conversation the employee has every reason to keep private from their employer. None of your controls are in that conversation, and no amount of phishing simulation reaches it.
The exposure is concentrated exactly where it hurts. Developers hold repository access, cloud keys and production credentials, and they are the demographic this operation targets by design. A developer who runs an attacker's coding assessment on the same machine that holds a valid session to your source control has handed over a path into your environment without ever touching a corporate email.
There is a second-order risk on the hiring side. The proxy recruitment Silent Push describes exists so that a North Korean operator can pass your interview using someone else's identity. That makes identity verification a security control in your recruiting process, not just a compliance step, particularly for remote engineering roles.
- Send your engineering organization a short, non-judgmental note naming this specific pattern: unsolicited recruiter, coding assessment, run this project locally. Say plainly that running it on a machine holding company credentials is the risk, and offer a clean sandbox for anyone who wants one. People job-hunt; pretending otherwise gets you nothing.
- Shorten session lifetimes and require reauthentication for source control, package registries and cloud consoles on developer endpoints, so a stolen session token expires before it is useful.
- Work with HR and talent acquisition on identity verification for remote technical hires, including checks that detect a candidate whose interview presence and working output do not match.
- Hunt for the documented families in the advisory across developer endpoints, and review recent logins to repositories and cloud accounts from new devices or unusual network paths.
Follow-up: the Linux kernel KEV deadline landed today, and CISA is asking for forensic triage
NOTABLE · UPDATE TO A PRIOR EDITIONCVEs: CVE-2025-39682 (kernel TLS receive path), CVE-2026-53266 (ebtables SNAT ARP rewrite), CVE-2025-39964 (AF_ALG socket race condition)
Federal remediation date: end of September 21, 2026
Additional requirement: CISA marked all three as requiring forensic triage of every affected asset
Age: CVE-2025-39964 was present in the Linux kernel for 14 years
Exploit status: Red Hat confirms public exploit availability for CVE-2025-39682 and a known exploit for CVE-2026-53266
Ransomware use: none of the three is currently flagged as used by ransomware groups
What happened
We covered these three kernel flaws when CISA added them to the Known Exploited Vulnerabilities catalog on September 18. Two things changed today. The federal remediation deadline fell at the end of September 21, and CISA attached a forensic triage requirement, meaning agencies must examine each affected asset for evidence that exploitation already happened rather than simply patching and closing the ticket. CISA has still not described the incidents or the actors behind them.
Detail also firmed up on provenance. Offensive security firm STAR Labs found CVE-2025-39964, a bug that had been in the kernel for 14 years, and demonstrated privilege escalation and container escape with it in Google's kernelCTF. The firm noted its researchers found the issue without help from an AI system. Red Hat has confirmed that public exploit code exists for CVE-2025-39682 and that a known exploit exists for CVE-2026-53266. Researcher Kimmo Suominen published a technical analysis and patch-status tracker for CVE-2026-53266 and is careful to say the privilege-escalation chain he outlines is inferred by analogy with Dirty Pipe and has not been shown working in public exploit code.
Evidence
Verified against two independent sources:
1. BleepingComputer, "CISA alerts of active exploitation of three Linux kernel flaws," September 21, 2026
2. The Hacker News, "CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild," September 19, 2026
What this means for your team
The forensic triage flag is the part to carry into your own program even though you are not bound by the directive. It says the agency believes exploitation may already have occurred on assets that are still unpatched, which reframes the work from a patch job into an investigation. If your organization patches to a KEV deadline and stops there, you are answering a different question from the one CISA is asking.
Note also what these bugs are. All three need a local foothold first. Teams that tier patching by whether a flaw is remotely reachable will have scored them low, which is precisely why they are useful to an attacker who already landed through something else. Container escape, as demonstrated in kernelCTF, is the reason this matters to anyone running multi-tenant workloads.
- Confirm kernel patch status across servers, container hosts and appliances, and treat unpatched multi-tenant container hosts as the priority given the demonstrated escape.
- Adopt the forensic triage step on any asset that stayed unpatched past disclosure: look for unexplained privilege escalation, new kernel modules and container boundary anomalies rather than assuming the patch closed the story.
- Revisit how your severity model treats local privilege escalation. If a confirmed-exploited local flaw cannot reach your expedited patch queue, the model needs changing, not the exception process.
Also notable
Items that scored well on our ranking but sat below the threshold for full treatment today. Each is sourced; none has been verified to the two-source standard we apply above.
- Technical details and proof-of-concept code were published for a WordPress core cross-site request forgery flaw called Click2Shell that can be chained to execute PHP on the server. BleepingComputer
- Ireland's Data Protection Commission fined Google 403 million euros, about $463 million, over how three features handled location data between May 2018 and February 2020, and ordered the processing brought into compliance within six months. The Hacker News
- SentinelOne attributed the compromise of an India-based IT services provider to the North Korean group Jade Sleet, using macOS backdoors tracked as FLATROOF and ROOFDECK. The Hacker News
- Blackpoint researchers documented a previously undocumented remote access trojan called ChainScript, delivered through ClickFix-style lures and using a Polygon smart contract to locate its command infrastructure. The Hacker News
- Securonix detailed a PowerShell backdoor campaign called TASK#STOMP that harvests business documents, Wi-Fi passwords and clipboard contents through two redundant command servers. The Hacker News
- The ShinyHunters extortion group defaced the Clop ransomware operation's leak site and claims to have taken server data and the private keys for its onion service. The claim comes from the attackers and has not been independently confirmed. BleepingComputer
FAQ
What is an EDR killer, and how is it different from ordinary malware?
An EDR killer is a component whose only job is to disable endpoint detection and response and antivirus software so that other malware can run unobserved. It works by loading a kernel driver, which sits below the layer where security agents operate, and terminating their processes from there. Ordinary malware tries to avoid detection; an EDR killer removes the thing doing the detecting.
If a driver is signed by Microsoft, why is it not safe?
Microsoft's hardware compatibility signing confirms that a driver passed through an attestation pipeline. It does not assess whether the driver's behavior is malicious or whether it can be abused. The driver in this campaign was signed in March 2023, years before the attackers used it, and Microsoft told the researchers that its behavior does not meet the company's definition of a security vulnerability because the driver is not a Microsoft component.
Does Microsoft's vulnerable driver blocklist stop this?
Not in this case. The blocklist is on by default on current Windows builds, but it matches known file hashes. A renamed or recompiled driver produces a new hash and is not covered. Here the original driver had never been added either, so the file was not blocked before or after the rename.
Was LastPass itself breached?
No. LastPass says none of its systems, services or customer vaults were touched. The attackers created a fake GitHub page using the LastPass name and product imagery as a lure. The same infrastructure was serving impersonation pages for at least 40 brands.
Was the BigCommerce platform itself breached?
BigCommerce says its platform and systems were not breached. The compromise was of credentials belonging to two third-party applications, Ribon and Ribon 1.5, operated by an outside company. Those credentials were then used to reach shopper records held in merchant environments.
Which data was exposed in the BigCommerce incident?
At Master of Malt, the retailer that has described the impact publicly, the exposed fields were full names, email addresses, phone numbers and shipping postal addresses. BigCommerce says account passwords and payment card information are stored separately and were not exposed. The retailer has said the incident may reach well beyond its own customer base.
Why should a CISO care about a campaign that targets individual developers?
Because the agencies issuing the advisory say the individual is the entry point rather than the objective. Their assessment is that a compromised developer gives the operators a route into the organization that employs them, supporting espionage, intellectual property theft and lateral movement. Developers also hold repository access and cloud credentials, which makes them a high-value foothold.
What does CISA's forensic triage requirement mean in practice?
It means patching alone is not the expected response. For each affected asset, the agency expects an examination for signs that exploitation already occurred. For a private-sector team, the practical translation is to investigate assets that remained unpatched after disclosure rather than closing the ticket once the update is applied.
Related reading from the community: past editions and analysis in the Breach Intelligence briefing archive, practitioner material on supply chain security for third-party integrations, guidance on building a vulnerability management program around exploited flaws, and the wider library of frameworks and checklists on CISO Platform.

Comments