TL;DR for CISOs: Researchers documented a threat actor running autonomous AI agents that scanned, exploited and skimmed more than 100 e-commerce sites with almost no human direction, stealing over 600,000 payment card records from 27 confirmed companies in five days at a cost of roughly 25 dollars per target. Separately, a WordPress remote code execution flaw patched on September 22 went from zero to a tenfold spike in exploitation traffic within a day. Zyxel network switches and a Veeam backup agent are both under confirmed active exploitation, with nearly a thousand Zyxel devices already compromised across 48 countries. And a Chinese state-linked group chained a Chrome and Windows zero-day together to install custom malware on Asian government systems.
- Autonomous AI agents can now scan, exploit and monetize a web application end to end for about the price of a business lunch. If your web application firewall and bot-detection controls were tuned for human-paced attacks, they are tuned for the wrong adversary now.
- A patch date is not a safety date. The WordPress flaw covered today sat quietly for one day before exploitation traffic jumped tenfold; the gap between "patched" and "verified clean" is where most of today's damage happens.
- Three unrelated vendors, Zyxel, Veeam and WordPress, are all under active attack this week using ordinary, well-understood flaw classes: buffer overflows, privilege escalation and path traversal. None of this requires novel tradecraft to defend against, only current patching and default-credential hygiene.
Lead story: Autonomous AI agents breach 27 companies in five days, steal 600,000+ credit cards
CRITICAL · ACTIVE CAMPAIGNResearcher: Threat intelligence firm Gambit, campaign tracked from July through mid-September 2026
Scale: 600,000+ credit card records stolen from two organizations; 119+ websites compromised with card skimmers; 27 confirmed companies breached in a single five-day window (September 10 to 15)
Cost: approximately 12,000 to 18,000 dollars total for the campaign, averaging about 25 dollars per targeted company
Tooling: three open-source AI agent frameworks chained together, Strix for reconnaissance and vulnerability scanning, Cairn for autonomous exploitation, Hermes for campaign orchestration and post-exploitation decisions
Targets: a Fortune 500 hospitality company, a major U.S. airline, and an industrial distributor, among others
Attribution: Gambit assesses the operator "appears to be Chinese" based on available evidence, with only brief human instructions directing largely autonomous execution
What happened
Gambit researchers identified a campaign in which a threat actor gave short instructions to a chain of three open-source AI agent frameworks and let automation carry out the rest of the attack with minimal ongoing supervision. Strix handled reconnaissance and vulnerability scanning against target e-commerce sites, Cairn carried out autonomous exploitation to gain shell or administrative access, and Hermes orchestrated the overall campaign and decided what to do after each compromise. Researchers logged 105 distinct attack waves between September 10 and 15 alone.
Once inside a target, the agents injected skimming code through several methods: appending malicious code to legitimate JavaScript files, modifying database fields that render on checkout pages, poisoning content delivery network assets, and altering Kubernetes deployment configurations. The campaign also automated its own cleanup, wiping stolen card data from compromised databases after exfiltration, which caused additional operational disruption for victims beyond the theft itself.
Across the full campaign window, Gambit counted more than 119 compromised websites and confirmed 600,000-plus stolen credit card records from two organizations alone, with 27 companies confirmed breached in the five-day peak period. Named victim categories include a Fortune 500 hospitality company, a major U.S. airline, and an industrial distributor. The total operating cost, an estimated 12,000 to 18,000 dollars, works out to roughly 25 dollars per targeted company, a price point researchers say puts this attack model within reach of far less skilled operators than the ones typically capable of running a campaign at this scale.
Evidence
Verified against independently fetched sources:
1. BleepingComputer, "Malicious AI agents steal 600K credit cards, infect 100+ sites with skimmers," September 23, 2026
2. Gambit threat intelligence research, as reported and corroborated by BleepingComputer's review of the underlying findings
What this means for your team
The economics changed, not just the tooling. A campaign that once required a skilled operator's time now runs on off-the-shelf, open-source agent frameworks at a cost of about 25 dollars per target. Any defense strategy that assumes attacker effort scales with the value of the target no longer holds; low-value and high-value sites alike are now cheap to hit.
Detection has to shift from noticing a slow, human-paced intrusion to catching a fast, automated one. The agents in this campaign moved from reconnaissance to exploitation to skimmer deployment to cleanup inside a single short engagement window per target. If your monitoring is built around alert fatigue thresholds tuned for manual attacker behavior, an automated chain like this can complete before a human analyst would normally look twice.
Checkout-page integrity monitoring is no longer optional for any organization processing payments online. The injection techniques here, from CDN poisoning to Kubernetes configuration changes, bypass simple file-integrity checks on the web server itself, so monitoring needs to cover the full delivery chain a customer's browser actually loads.
- Deploy or verify checkout-page integrity monitoring (subresource integrity, content security policy reporting, or a dedicated client-side script monitoring tool) across every payment flow you operate, not just your primary domain.
- Review CDN configuration change logs and Kubernetes deployment histories for the past 90 days for unexplained modifications, since both were confirmed injection vectors in this campaign.
- Re-tune web application firewall and bot-detection thresholds for automated, high-speed reconnaissance-to-exploitation chains rather than only human-paced attack patterns.
- If you operate e-commerce infrastructure in hospitality, aviation, industrial distribution or adjacent sectors named in this campaign, treat this as an active threat and review recent checkout-page code changes now rather than waiting for a customer complaint.
A WordPress flaw patched yesterday is under active attack today
CRITICAL · ACTIVELY EXPLOITEDCVE-2026-87902: unauthenticated path traversal in WordPress core, CVSS 9.2, affects versions 4.7 through 7.1.1
Mechanism: under specific conditions, a theme directory name beginning with "page-" combined with a vulnerable PHP file outside the active theme allows remote code execution
Patch released: September 22, 2026, in WordPress 7.1.2
Exploitation timeline: attackers moved from reconnaissance to payload delivery within hours of the patch; malicious traffic increased tenfold by September 23
Payload behavior: observed payloads write executable files to /tmp and /var/tmp
Particularly exposed: WordPress Docker images and cPanel default configurations running PHP versions below 8.5
What happened
WordPress shipped version 7.1.2 on September 22 to patch CVE-2026-87902, an unauthenticated path traversal flaw affecting every core version back to 4.7. The bug allows an attacker to include readable PHP files located outside a site's active theme directory; when a theme directory name happens to begin with "page-" and a suitable PHP file exists elsewhere on the server, the traversal escalates to remote code execution.
Exploitation followed the patch almost immediately. Attackers shifted from scanning and reconnaissance to actual payload delivery within hours of the fix going public, and observed malicious traffic increased roughly tenfold by September 23. Confirmed payloads write executable files into the /tmp and /var/tmp directories, consistent with attackers establishing persistence or a foothold for further action. The flaw affects WordPress core itself rather than a plugin, and researchers flag WordPress Docker images and cPanel installations running PHP versions older than 8.5 as particularly exposed configurations. Given that WordPress powers a substantial share of all websites globally, the theoretical exposure is measured in the millions of sites, though actual code execution requires the specific directory-naming condition described above.
Evidence
Verified against independently fetched sources:
1. BleepingComputer, "Hackers start exploiting critical WordPress flaw for code execution," September 23, 2026
2. Server log and indicator-of-compromise data cited in the same report, cross-checked against the September 22 WordPress 7.1.2 release notes
What this means for your team
Patch velocity now has to match attacker velocity, not the other way around. A tenfold jump in exploitation traffic within a day of a patch shipping means the window to update before attackers notice is measured in hours, not the days or weeks many change-management processes assume.
If you manage or host WordPress sites for clients, audit theme directory naming conventions specifically. This flaw's real-world impact depends on a directory name pattern that is easy to check for and easy to avoid going forward, which makes it a rare case where a configuration review can meaningfully reduce risk beyond the patch itself.
- Update every WordPress instance you manage to 7.1.2 immediately, prioritizing sites running PHP below version 8.5 or built from Docker images.
- Check active theme directory names for anything beginning with "page-" and rename or review them even after patching.
- Review server logs and /tmp and /var/tmp directories for unexpected executable files, and block the published indicator IP addresses 169.58.48.193, 169.58.48.195 and 2001:df1:e8c0::106b.
- If you patched before the exploitation surge began on September 23, still review logs from the patch window forward, since the flaw was reachable in the hours between release and your update.
Zyxel switches and a Veeam backup agent are both under active exploitation
HIGH · ACTIVELY EXPLOITEDCVE-2026-7273: Zyxel GS1900 series smart managed switches, CVSS 8.8, stack-based buffer overflow allowing unauthenticated, LAN-based OS command execution via crafted HTTP requests
Zyxel scale: 996 devices compromised across 48 countries, heaviest impact in Italy, the U.S., Taiwan, South Korea and the EU; 564 victims were using factory default credentials
Zyxel attribution: a suspected Chinese-speaking threat actor, active since on or about August 17, linked to earlier WordPress and Gitea infrastructure attacks
CVE-2026-32996: Veeam Agent for Microsoft Windows, CVSS 7.3, local privilege escalation to SYSTEM by abusing cached elevated session data readable by standard users
Veeam confirmation: active exploitation confirmed by security firm Arctic Wolf
Federal deadline: CISA ordered U.S. federal agencies to patch the Zyxel flaw by September 24, 2026
What happened
Security researchers confirmed active exploitation of CVE-2026-7273, a stack-based buffer overflow in Zyxel's GS1900 series smart managed switches running firmware 2.90(XXXX.1)C0 or earlier. The flaw lets an unauthenticated, LAN-based attacker execute operating system commands through specially crafted HTTP requests. GreyNoise tracked attacks beginning on or about August 17, attributed to a suspected Chinese-speaking threat actor previously linked to attacks on WordPress and Gitea infrastructure. As of this reporting, 996 devices across 48 countries have been compromised, with Italy, the United States, Taiwan, South Korea and several EU nations hit hardest. Attackers used the exploit to run TFTP tools that retrieved device configurations, hashed credentials and network information; notably, 564 of the compromised devices were still running factory default credentials, meaning the buffer overflow was often the second layer of an already-weak defense.
Separately, security firm Arctic Wolf confirmed active exploitation of CVE-2026-32996, a local privilege escalation flaw in Veeam Agent for Microsoft Windows. An attacker with local, standard-user access can read cached elevated session data left in logs, obtain a valid session identifier, and use it to execute commands with SYSTEM-level privileges. Unlike the Zyxel flaw, this one requires existing local access to a machine, making it most relevant as a second-stage escalation tool rather than an initial entry point.
Evidence
Verified against independently fetched sources:
1. The Hacker News, "Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access," September 22, 2026
2. Help Net Security, "Attacker compromised nearly 1000 Zyxel switches since August (CVE-2026-7273)," September 22, 2026
What this means for your team
More than half of the compromised Zyxel switches were reachable because of factory default credentials, not just the software flaw. A patch alone will not close that gap; every internet-facing or LAN-managed network device still on default credentials should be treated as already compromised until proven otherwise, regardless of whether it runs Zyxel firmware.
The Veeam flaw is a reminder that backup infrastructure is a privilege escalation target, not only a ransomware target. An attacker who already has a foothold on a machine running Veeam Agent can use this flaw to jump straight to SYSTEM, which changes what a routine endpoint compromise can turn into.
- Patch Zyxel GS1900 switches to firmware released after June 2026 immediately, and separately audit every managed switch on your network for factory default credentials.
- Check GreyNoise's published indicator-of-compromise list for the Zyxel campaign against your own device logs.
- Patch Veeam Agent for Microsoft Windows to the fixed release, and review local session logs on machines running the agent for unexplained elevated-session activity.
- Federal agencies and any organization following CISA's Known Exploited Vulnerabilities guidance should treat September 24 as the Zyxel patch deadline.
A Chinese state-linked group chained a Chrome and Windows zero-day to hit Asian governments
HIGH · NATION-STATEThreat actor: UTA0565, a Chinese state-linked group
Vulnerabilities chained: CVE-2026-85046 and CVE-2026-87491 (Google Chrome), CVE-2026-85880 (Windows Advanced Local Procedure Call)
Attack window: observed September 3 to 4, 2026
Delivery: phishing emails impersonating media outlets and NGOs, directing targets to fraudulent domains including "chinadigitaltimes[.]top" and "americanprgoress[.]top"
Payload: custom malware dubbed CLEANGULP, communicating via a command-and-control domain impersonating a legitimate academic publication
Targets: Asian government entities, with lures referencing Hong Kong activist Chow Hang-tung
What happened
Researchers documented UTA0565, a Chinese state-linked threat actor, chaining two Chrome vulnerabilities, CVE-2026-85046 and CVE-2026-87491, with a Windows Advanced Local Procedure Call flaw, CVE-2026-85880, to bypass browser sandboxing and achieve remote code execution as zero-days. The campaign, observed September 3 and 4, 2026, used phishing emails written in Chinese and English, impersonating media outlets and NGOs and referencing Hong Kong activist Chow Hang-tung, to direct Asian government targets to fraudulent websites spoofing domains such as "chinadigitaltimes[.]top" and "americanprgoress[.]top."
Victims who visited the fraudulent sites were silently exploited through the chained zero-days and infected with CLEANGULP, custom malware capable of command execution, process enumeration, and file upload and download, along with support for beacon object file execution, a technique commonly used to extend malware capability without dropping additional files to disk. CLEANGULP communicates with infrastructure disguised as "thecovnresation[.]com," a domain designed to visually mimic a legitimate academic publication.
Evidence
Verified against independently fetched sources:
1. The Hacker News, "Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware," September 23, 2026
2. The Hacker News, "Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox," September 2026, on the underlying CVE-2026-85046 patch and advisory
What this means for your team
Browser patch cadence is a nation-state defense control, not just hygiene. This is the second Chrome zero-day chained into real-world nation-state attacks this year to reach public reporting; organizations that delay browser updates for compatibility testing should shorten that window specifically for actively exploited Chrome advisories.
If your organization has any connection to government, NGO, media, human rights or Hong Kong-adjacent policy work, treat lookalike-domain phishing referencing current political figures as a targeted risk, not generic spam, and brief relevant staff accordingly.
- Confirm Chrome is fully patched against CVE-2026-85046 and CVE-2026-87491, and Windows against CVE-2026-85880, across all managed endpoints.
- Block or monitor the identified malicious domains, "chinadigitaltimes[.]top," "americanprgoress[.]top" and "thecovnresation[.]com," at the DNS or proxy layer.
- Configure endpoint detection to flag beacon object file execution patterns, which CLEANGULP relies on to extend its capability.
- If your organization has government, NGO, media or human-rights adjacent functions, brief staff on lookalike-domain phishing tied to current political events specifically.
Also notable
Items that scored well on our ranking but sat below the threshold for full treatment today. Each is sourced; none has been verified to the two-source standard we apply above.
- cPanel patched three vulnerabilities in its CalDAV/CardDAV service and WP Toolkit, including CVE-2026-87899, which lets any logged-in hosting account execute code as root and take full server control with no special permissions required. Not yet listed in CISA's Known Exploited Vulnerabilities catalog as of publication, but hosting providers should treat root-level flaws as urgent regardless. The Hacker News
- The F5 BIG-IP APM (CVE-2026-94127) and Arista VeloCloud Orchestrator (CVE-2026-93952) zero-days covered in yesterday's edition remain under active exploitation; CISA's federal patch deadlines land September 24 and 25 respectively, and organizations that have not yet patched should treat this as still urgent, not stale news. BleepingComputer
- The FBI has still not confirmed or denied ShinyHunters' claimed breach of FBIjobs.gov reported yesterday; the agency continues to say only that it is investigating. We will update this briefing when either side provides confirmation. The Record
FAQ
What is AI-agent-driven web skimming, and how is it different from a typical Magecart attack?
A typical Magecart-style skimming attack is carried out or directed step by step by a human operator, using known tools against known targets. AI-agent-driven skimming, as documented in this campaign, chains together autonomous AI frameworks that independently scan for vulnerable sites, exploit them, deploy skimming code and clean up evidence, with a human only providing brief initial instructions. The result is a campaign that scales to over 100 targets at a fraction of the cost and time a human-operated version would require.
How many companies and credit cards were affected by the AI agent campaign?
Researchers confirmed at least 27 companies breached in a five-day window from September 10 to 15, 2026, with more than 119 websites compromised across the full campaign that ran from July through mid-September. Over 600,000 credit card records were confirmed stolen from just two of the affected organizations.
Is the WordPress CVE-2026-87902 flaw now being exploited, and what changed since it was patched?
Yes. WordPress patched the flaw on September 22, 2026 in version 7.1.2. Attackers began exploiting it within hours of the patch's release, and observed malicious traffic increased roughly tenfold by September 23, with payloads writing executable files to server temp directories.
What CVEs are involved in the Zyxel and Veeam active exploitation, and how many devices were compromised?
The Zyxel flaw is CVE-2026-7273, a buffer overflow in GS1900 series switches, with 996 devices confirmed compromised across 48 countries. The Veeam flaw is CVE-2026-32996, a local privilege escalation bug in Veeam Agent for Microsoft Windows; no device count has been disclosed for that vulnerability.
Who is UTA0565, and what is CLEANGULP malware?
UTA0565 is a Chinese state-linked threat actor that researchers observed chaining two Chrome zero-days with a Windows zero-day to compromise Asian government targets in early September 2026. CLEANGULP is the custom malware the group deployed after exploitation, capable of command execution, file transfer and beacon object file execution for extended capability without dropping additional files to disk.
Are the F5 and Arista zero-days covered yesterday still a risk today?
Yes. Both CVE-2026-94127 (F5 BIG-IP APM) and CVE-2026-93952 (Arista VeloCloud Orchestrator) remain under active exploitation, with federal patch deadlines of September 24 and 25 respectively under CISA's Known Exploited Vulnerabilities catalog. Organizations that have not yet patched should not treat this as resolved.
Has the FBI confirmed the ShinyHunters breach claim from yesterday?
No. As of this edition, the FBI has said only that it is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is investigating. Neither a breach nor the scope of any data theft has been confirmed by the agency.
Related reading from the community: past editions and analysis in the Breach Intelligence briefing archive, practitioner material on building a vulnerability management program around exploited flaws, guidance on application and web security for e-commerce environments, and the wider library of frameworks and checklists on CISO Platform.

Comments