Retour au blog
Numéro 9Evolve on SundaysCyber DefenseTechnologyEducationA la une

Evolve on Sundays: Cisco Intrusions Lead to Ransomware, Hackers Steal Cloud Access, Apple Unveils a Foldable iPhone, NASA Releases Lunar AI and Kiro Turns Prompts into Code

Also inside: GitLab fixes secret-exposure flaws; Adobe confirms Commerce exploitation; BlueMoon breaches Chrome and Windows; attackers seize Artifactory admin access; .NET 11 improves builds; LTM joins Lightwell remediation.

Autrice
ALAIsha Lalli
Publié
Sep 13, 2026
Temps de lecture
18 min read

Reporting for September 6-12, 2026. Two security pages, one technology page, and one technical education page. Earlier activity is dated explicitly; attribution and vendor findings remain attributed.

01Security Headlines

Cisco FMC intrusions lead to credential theft and ransomware

Cisco Talos advisory artwork Cisco Talos. September 9 investigation.

September 9 reporting; earlier vulnerability disclosure: Cisco's firewall-management investigation concerns the management plane, not a newly disclosed flaw in every Cisco firewall. The advisory for CVE-2026-20079 was first published on March 4 and updated this week. Cisco traces the authentication bypass to an improper process created at boot: crafted HTTP requests permit script execution with root access. The affected products include Secure FMC and SCC Firewall Management; Cisco says its SaaS management environments have received the fix. ASA, FTD and Firewall Device Manager are excluded from this advisory's affected-product list. Cisco authentication-bypass advisory.

A second entry point, CVE-2026-20316, exposes a low-privileged account through static credentials. Its 5.3 CVSS score describes that individual weakness. Cisco assigns a higher security-impact classification because it can combine with other FMC weaknesses to obtain greater privileges. Internet isolation reduces reachability; it does not change whether an installed version contains the flaw. Cloud-delivered FMC is explicitly excluded from this second advisory. Cisco static-credential advisory.

Talos identifies three distinct intrusion clusters

UAT-12197: Talos found a JSP web shell in the Tomcat webroot, followed by a JAR command executor. That executor invoked FMC's database tooling to extract user authentication records. The consequential transition was from appliance execution to stored credentials.

UAT-11823: The actor replaced a licensing package and used the legitimate package_info.pl utility to execute it as root. Reverse-shell access preceded configuration collection and deployment of a Cyclops Blink variant. Talos reports tooling overlap with Sandworm; that is an attributed relationship, not proof that every cluster shares an operator.

UAT-11988: Static-account access led to privileged package execution, AD and database credential collection, and internal host mapping. SOCKS and reverse-SSH tunnels exposed directory, file-sharing and remote-management services to the operator. Subsequent endpoint activity included antivirus killers and Qilin ransomware.

These are separate observed intrusion sequences. The public report does not establish a single start date or victim count for all three. Talos acknowledged Avit's contribution to the ransomware investigation. Talos investigation.

Cisco warns hotfixes may leave existing compromise

Cisco distinguishes preventing re-entry from recovering an already compromised appliance: hotfixes “may not address existing compromise.” Its advisory identifies licensing-package execution in system logs as a possible indicator and directs suspected compromises into TAC recovery. Hotfixes are listed for the 7.0, 7.2, 7.4, 7.6, 7.7 and 10.0 release families. Installed fixes therefore establish remediation of the entry vulnerability, not removal of stolen credentials or downstream persistence. Recovery and hotfix details.

GitLab fixes file-read and Duo Chat credential-exposure flaws

GitLab illustration SecurityWeek illustration; reused from August 23.

September 10: GitLab's 19.3.2, 19.2.6 and 19.1.8 releases close two critical weaknesses with different prerequisites. CVE-2026-85706 combines missing authentication enforcement with improper path confinement in the repository commits API, enabling unauthenticated arbitrary-file reads under conditions the notice does not fully disclose. It affects CE and EE from 18.7, with fixes at the versions above.

CVE-2026-87719 instead requires an authenticated EE user with Duo Chat access. A crafted GraphQL subscription argument bypasses serialization and performs server-object lookup, exposing Advanced Search configuration and credentials. Its affected range begins at 18.3, not 18.7. The common fixed releases must not obscure the different exposure populations.

GitLab.com was already patched; Dedicated customers required no action. The advisory credits separate bug-bounty researchers and does not report exploitation of these two flaws. Detailed issue records are normally opened 90 days after remediation. Until then, the public evidence supports the affected interfaces, prerequisites and disclosed impact, but not a complete exploit reconstruction or an assertion that credentials were stolen from any particular deployment. GitLab release and version ranges.

Adobe confirms Commerce exploitation and urges credential rotation

September 7 bulletin; response guidance updated September 11: Adobe confirms exploitation of CVE-2026-75650, an unauthenticated template-engine weakness rated CVSS 10.0. Its bulletin covers Commerce, Commerce B2B and Magento Open Source, including the listed August 2026 builds and earlier releases. A hotfix addresses arbitrary code execution. Adobe has not published a campaign timeline, victim count or attacker attribution in the bulletin. APSB26-146.

The recovery instructions explain why a patched storefront can leave exposure elsewhere. Commerce's encryption key protects integration tokens, payment-gateway credentials and privileged automation tokens. An attacker who has obtained the underlying credentials can keep using them against external services after the local encryption key changes.

Adobe states: “Rotating the encryption key alone does not invalidate credentials that may already have been exposed.” Its response therefore includes rotation at the issuing services, alongside replacement of integration tokens, administrator passwords and deployment credentials. The distinction is specific: changing encryption protects newly stored material; invalidating a payment-provider credential removes authority accepted by that provider. Adobe's guidance establishes the recovery scope, not evidence that every affected merchant lost every listed secret. Adobe recovery guidance.

02Security Investigations

Espionage groups use BlueMoon to breach Chrome and Windows

BlueMoon crosses V8 memory isolation and the Windows renderer boundary Reported exploit stages. Evolving Cyber, based on Proofpoint.

September 9 disclosure; activity from August 28: Proofpoint identified four espionage clusters using BlueMoon. The chain couples V8 type confusion, CVE-2026-85046, with a V8 sandbox escape, CVE-2026-87491, then a Windows kernel privilege escalation, CVE-2026-85880, to escape the renderer process. The V8 sandbox and the operating-system process boundary are separate barriers.

The browser fixes were already visible in upstream Chromium before reaching stable releases. Proofpoint dates the first fix to August 7 and its stable delivery to September 3. The Windows component, however, targets older builds, narrowing the population on which the complete chain works.

Host fingerprinting determines whether to attempt kernel exploitation. A further injection stage runs an operator-selected command through Chrome's broker process. The researchers report common exploit machinery across campaigns, but say: “It is currently unknown how multiple distinct threat actors obtained access to the exploit kit.” Diagnostic comments and a handover document support their hypothesis of AI-assisted development; neither establishes authorship. Proofpoint research.

University-site XSS redirects victims to browser exploits

Volexity independently describes September 1 NGO targeting through a university website's reflected XSS flaw. That trusted site redirected victims to an exploit page displaying a donation-form decoy. The loader filtered for Chrome on Windows, then invoked the exploit through a hidden iframe. A URL parameter selected the eventual payload, allowing operators to change the malware without replacing the core exploit page.

Volexity observed byte-identical shellcode in UTA0560 and JungleBamboo delivery, followed by different payloads. UTA0560 deployed the GRIMWEDGE JScript backdoor; JungleBamboo installed a credential-stealing extension disguised as Google Gemini. Identical shellcode is evidence of shared components, not sufficient evidence of one operator. Volexity describes a possible common supplier or broker as an interpretation.

The backdoor analysis also separates capabilities from completed actions: file-read and upload commands create an exfiltration capability, while additional activity still requires execution. The reported scheduled-task and extension artifacts sit beyond the original browser entry point. Volexity investigation.

Google's September 8 stable-channel notice confirms exploitation of CVE-2026-87491. That vendor confirmation establishes active use of the vulnerability; it does not independently establish the attribution or AI-development hypothesis in the research reports. Chrome release notice.

Attackers use passkey lures to steal cloud access

Device-code approval sends a token to the requesting client An authorization flow, not a break in passkey cryptography.

September 9 reporting; activity since May: Microsoft separates three patterns: AiTM theft of credentials and session tokens; device-code approval that issues a token to an attacker-controlled client; and reuse of credentials with an authenticator registered during an earlier compromise.

One investigated session completed MFA at T+1 minute, enumerated assigned applications at T+2, and reached account/security interfaces at T+3 to T+4. SharePoint and mailbox-related access followed during an approximately hour-long session. Those timestamps describe one sequence, not every victim.

Microsoft cautions: “The sign-in events do not prove that a document was opened or downloaded.” An attachment-resource authentication and entry into a virtual-desktop authentication flow likewise did not establish completed downloads or a launched desktop. Personal-phone lures could fall outside managed-endpoint telemetry, making employee recollection part of the initial-access reconstruction.

The actor also enrolled authentication methods for future access. Microsoft describes that persistence as dependent on remaining credentials or sessions, rather than an authenticator that survives every reset. Its response spans token/session revocation and removal of unauthorized factors and mailbox rules. The published account does not quantify victims or confirm every downstream action. Microsoft investigation.

Anthropic disrupts AI-assisted credential theft and intrusions

Anthropic September threat report artwork Anthropic's September 10 threat report.

September 10: Anthropic reports disrupting suspected ShinyHunters affiliates whose workflows combined conventional secret harvesting with model-assisted intrusion. One operator used ten EC2 workers to download 1.8 million APKs, decompile them and scan with TruffleHog. Validated results went to Telegram; a separate GitHub pipeline supplied personal access tokens. The APK total counts processed applications, not compromised organizations.

A different affiliate used a SaaS foothold to reach roughly 200 downstream customers and dumped more than 2,100 Azure AD token sets across over 40 tenants in about 34 hours. These are separate operations in the report, not later steps of the APK pipeline.

Anthropic describes models interpreting unfamiliar APIs, building export tools and expanding access while operators supplied objectives. One stolen AI key supported secondary attacks for roughly three weeks. Anthropic says the keys came from customer environments, not a breach of its own systems. It banned associated accounts and engaged victims and authorities. The reported scope reflects the provider's investigation; full victim identities and independent reconciliation of every dataset remain unavailable in the public account. Anthropic report.

Attackers chain Artifactory flaws to gain admin control

September 10 investigation; attacks observed August 15-September 8: Wiz reports attackers chaining two flaws against self-hosted Artifactory. CVE-2026-42018 returns an internal anonymous-user token even with anonymous access disabled. CVE-2026-42016 accepts its signature and issuer without enforcing scope, allowing exchange for administrator authority. The username remains anonymous: the log identity alone understates its power.

Some intrusions reached a persistent administrator account in under five minutes. Across cases, attackers installed malicious Groovy plugins for server-side execution and deployed Rust backdoors. Wiz cautions: “No single actor ran every step below.” These observations describe several intrusions, not one universal payload sequence.

A separate route, CVE-2026-82329, was observed September 1-8: an unauthenticated request to the registry-join endpoint returned an administrator token. Subsequent activity included configuration extraction, new credentials and cluster join-key theft. This route does not require the earlier two-flaw chain. The report establishes repository-server compromise; it does not identify a confirmed downstream release contaminated through these intrusions. Wiz investigation.

Earlier response, August 28: JFrog disclosed the standalone authentication bypass under default configuration and issued branch-specific fixes, including 7.161.20, 7.146.38, 7.133.29, 7.125.20 and 7.117.28. Its advisory says affected cloud environments were already protected. That statement concerns JFrog's hosted service; the intrusion evidence above concerns self-hosted deployments. The vendor also documents an additional secret join key as an interim workaround, rather than treating network access as equivalent to authenticated cluster membership. JFrog advisory.

03Technology News

.NET 11 RC1 adds reproducible containers and live identity refresh

Microsoft .NET 11 RC1 release artwork Microsoft release artwork. September 8.

September 8: .NET 11 RC1 carries a go-live support license while remaining a prerelease. Microsoft supports it with Visual Studio 2026 Insiders and VS Code's C# Dev Kit. The engineering changes worth separating are artifact reproducibility and authentication changes on already-open connections. Release announcement.

Stable timestamps enable reproducible container digests

The SDK notes identify timestamps, archive headers and directory enumeration order as causes of differing container digests across repeated publishes. Setting SOURCE_DATE_EPOCH to a stable Unix timestamp makes independent publishes of identical inputs reproducible. That qualification matters: an unchanged source tree alone is not a claim that dependencies and base-image inputs are identical.

Publishing also checks whether the resulting manifest already exists in the destination repository. If it does, the SDK skips layer/configuration processing but still applies the requested tags. ContainerPushNoCache disables that manifest-level optimization; blob-existence checks still avoid re-uploading material already present. Reproducibility and upload avoidance are separate changes, with different triggers.

The same release introduces run-wide test limits and per-module results directories. Limits belong before the double-dash separator; arguments after it go to individual test applications. Per-module output prevents separate test programs from overwriting identically named result files. The default remains a flat directory. SDK implementation notes.

SignalR refreshes identity on open connections

Authentication refresh began in Preview 6; RC1 finalizes the SignalR APIs. A hub opts in, and the server can inspect or reject the replacement identity. Microsoft's example compares the previous and new subject identifiers before accepting the refresh. The client can renew ahead of expiry or request refresh after receiving changed claims.

Blazor Server circuits can receive the refreshed ClaimsPrincipal and raise AuthenticationStateChanged, causing components consuming that state to re-render. This addresses a specific mismatch: a long-lived connection can otherwise retain an identity snapshot while the application's roles or claims change elsewhere.

It is not a statement that every authorization decision is continuously reevaluated. The documented behavior is driven by authentication refresh and the components that observe its state. RC1 also changes preview callback and feature names, so preview adopters face API migration even though the underlying connection can remain open. ASP.NET Core notes.

NASA and IBM release an open lunar AI model

Nine instruments contribute spatially aligned layers to a lunar model Data preparation and evaluation. Evolving Cyber, based on IBM/NASA.

September 10: IBM and NASA released a lunar foundation model alongside an aligned dataset: more than 30 layers from nine instruments across four missions. The engineering contribution begins before training, with observations at different resolutions brought into a common spatial framework rather than treated as isolated instrument-specific tasks.

NASA's Kevin Murphy described the gap directly: “We also have to make data easier for scientists to explore and use.” The release describes ice-potential estimation, volcanic-feature segmentation and crater detection, with different metrics and resolutions for each.

Against SwinV2-B, the authors report up to 22% lower RMSE for high-potential ice areas and nearly 19% improvement for context-scale crater detection using half the training data. Meter-scale crater performance is described as comparable. These are author-reported task results, not one universal accuracy improvement. Predicted ice potential is not a confirmed deposit or a validated landing site. The open release enables scrutiny of data alignment and downstream evaluation; the announcement itself supplies no independent replication. IBM/NASA release and technical-paper links.

Apple unveils foldable iPhone with sliding glass layers

iPhone Duo shown folded and unfolded Apple product image; announced hardware, not independent testing.

September 9: Apple's first foldable iPhone pairs 7.6-inch and 5.4-inch displays with the same aspect ratio. Apple describes proportional content scaling across configurations; its launch announcement does not specify every application's state-restoration or multitasking behavior.

The mechanical account is more substantial than the screen dimensions. Glass layers above and below the folding panel use adhesives that permit relative sliding under bending, while a titanium plate supports the assembly. A polymer cover protects the inner surface; a hinge with more than 100 components supports the center when open. A20 Pro is paired with a vapor chamber and a dual-battery architecture. These are manufacturer descriptions of construction, not evidence of field reliability.

Touch ID moves authentication to the side button. Pre-orders begin October 16 and availability October 23; USB-C Apple Pencil support is promised later in the year. Those are three different delivery milestones. Apple's announcement supplies neither independent hinge-cycle results nor application-level compatibility measurements, so neither should be inferred from the launch specifications. Apple announcement.

LTM joins IBM and Red Hat to deploy Lightwell fixes

Red Hat Lightwell illustration Red Hat artwork from its Lightwell overview.

September 9: LTM announced a collaboration with IBM and Red Hat to integrate Lightwell remediation into enterprise software delivery. Its planned services cover dependency analysis, prioritization, DevSecOps integration, testing and deployment. The engineering boundary is between producing a corrected dependency and establishing that the application consuming it still behaves correctly.

Red Hat's Ryan King described the delivery constraint: “AI-driven discovery has pressed the demand for speed and patch delivery far beyond the means of any one single vendor.” The announcement provides no measured deployment times, regression rates or customer outcome data. It establishes a services commitment, not demonstrated end-to-end automation. September announcement.

Background, July 8 launch: Lightwell Network began with more than 6,500 remediated application dependencies, including Java and Python packages. IBM and Red Hat describe backporting fixes to long-lived production versions, delivering signed binaries, source and SBOMs through existing pipelines. Fixes are submitted upstream for review; delivery to customers and acceptance by the original project are separate events.

The second offering, Clearinghouse Premier, entered limited availability for financial services, coordinating targeted version remediation under disclosure embargoes. That restricted coordination service differs from the generally available package library. Neither a signature nor an SBOM demonstrates application compatibility: those artifacts support provenance and inventory, while regression validation remains a separate engineering question. Red Hat launch details.

04Education - Understanding Kiro

AWS's Kiro turns prompts into specs, code and tests

Kiro combines conversational coding with structured specifications Kiro launch artwork. Background: July 14, 2025.

What it is: Kiro is AWS's AI development tool. It works with a software repository to explain code, plan changes, write implementations and produce tests and documentation. AWS describes the service as built on Amazon Bedrock. Its defining idea is to make the requirements and design of a change explicit, then use those documents to guide the agent's implementation. This is what Kiro calls spec-driven development. AWS overview.

The point: Generating code quickly does not settle what the software should do. A working prototype can still contain undocumented assumptions about permissions, data handling, failure behavior or integration with the existing system. Kiro puts those decisions into reviewable artifacts so an engineer can correct the plan before the same assumption spreads through code and tests.

The launch authors, Nikhil Swaminathan and Deepak Singh, framed the problem directly: “What assumptions did the model make when building it?” Kiro entered preview on July 14, 2025, so its introduction is background to this lesson, not a launch this week. Original introduction.

Kiro plans, codes and tests changes

Kiro combines a coding environment with an agent that can work through development tasks. It can answer questions about an existing repository, help diagnose a defect, propose a feature design, edit the implementation and run validation. The desktop IDE is based on Code OSS, with support for VS Code settings and Open VSX-compatible extensions. Terminal and web interfaces provide other ways to work with the agent. An AWS account is not required to get started. Product overview.

Its structured feature workflow produces three central documents. requirements.md records user stories and acceptance criteria: what the change must achieve. design.md records the architecture, data flows and implementation approach: how it should work. tasks.md breaks that design into trackable implementation work. A bug-fix spec uses a bug analysis in place of the feature requirements. Spec documentation.

The practical benefit is a persistent account of the change. A reviewer can inspect the requirement behind a task and the design behind a code decision. When an assumption changes, the discussion has a concrete document to update. The documents are still generated proposals; their existence does not demonstrate that the design is sound or that the implementation satisfies it.

Specs expose assumptions before coding

Consider a team adding a reporting export to an established application. “Add CSV export” sounds straightforward, but leaves questions about authorized users, tenant isolation, excluded fields, maximum result size and consistency while records are changing. An agent could produce a plausible download button while silently choosing answers to all of them.

Kiro's spec workflow provides a place to surface those decisions before implementation. Requirements can define the allowed audience and output. The design can identify the existing authorization boundary and query path. Tasks can connect the interface change, server implementation and tests. This is an illustrative use case, not a report of an observed Kiro deployment.

The value becomes clearer during review. If the team later changes the export limit, reviewers can trace which behavior, query strategy and tests need to change. If a security reviewer disputes tenant handling, the disagreement can be resolved at the design level before a large patch is accepted. The same approach can apply to service integrations, refactoring and changes with several dependent components.

There is a cost to that structure. For a small, obvious correction, writing a full specification may add little. For a change with disputed behavior or architectural consequences, recording the decisions can be more valuable than immediately generating a larger diff. Kiro supports conversational work as well as specs; the useful choice depends on how much uncertainty the task contains.

Developers and reviewers share a plan

Developers working in existing codebases: The relevant capability is combining repository context with a plan for the change. This can help when implementation must fit established interfaces, conventions and tests. The engineer still has to verify that the agent found the right code paths and understood their behavior.

Technical leads and engineering managers: Reviewable requirements and task breakdowns can make scope disagreements and dependencies easier to discuss. They also leave a record that another engineer can read without reconstructing a long chat. A completed task list is a progress signal, not a substitute for delivery evidence.

Platform teams and architects: Shared project guidance can describe approved libraries, repository layout and architectural conventions. Its usefulness depends on whether that guidance reflects the system as it exists. Stale instructions can make generated changes consistently wrong rather than merely inconsistent.

Security engineers and CISOs: Kiro is relevant as a tool used by engineering teams to build and change software. Its specs offer an earlier place to examine trust boundaries and acceptance criteria. It does not replace a security review, provide an independent audit of its own output, or become a security operations platform simply because it can write security-related code. These are role-based implications of the documented workflow, not measured productivity claims.

Steering guides; hooks automate

Specs describe a particular change. They capture the desired behavior, design and implementation work for that feature or fix. They answer what this piece of work is intended to deliver.

Steering describes the project. Markdown files in .kiro/steering/ provide persistent context such as product purpose, technology choices and repository structure. Guidance can be loaded broadly or for matching files. This reduces the need to repeat conventions in each conversation. An instruction to use existing authorization middleware guides the agent; it does not itself enforce authorization in the running application. Steering documentation.

Hooks automate recurring actions. Kiro documents event triggers, optional matchers and actions in .kiro/hooks/. A command action can run a tool; an agent action provides instructions to the agent. Examples include running a linter after a relevant edit or checking companion documentation. Supported triggers vary by interface. Hooks make checks repeatable when correctly configured; they do not prove that the selected checks are sufficient. Hook documentation.

Kiro works locally and in the cloud

The IDE lets an engineer work in the workspace alongside the agent. The CLI brings the agent into a terminal workflow. Kiro Web can work on connected repositories in a cloud sandbox and prepare pull requests. Its documentation describes conversational iteration and autonomous execution, with configurable repository connections and sandbox access. Kiro Web.

That distinction matters operationally. Local collaboration keeps the edit-and-review loop close to the developer. Cloud execution supports handing off a bounded task, but the environment still needs the dependencies, fixtures and access required to validate it. A missing test database and an incorrect implementation can both produce a failed run; the execution evidence must distinguish them.

Engineers retain release decisions

Kiro's November 17, 2025 general-availability announcement introduced property-based testing for spec correctness: extracting general properties from requirements and checking them across generated inputs. This can explore cases beyond individually written examples. It remains bounded by the properties chosen and the behavior represented in the test environment. Testing background.

A specification can omit a requirement. A design can select the wrong boundary. Tests can reproduce the same misunderstanding as the implementation. Kiro makes these decisions more visible and helps perform the associated work; engineers remain responsible for judging whether the requirements are complete and whether the evidence supports release.

The useful outcome is therefore concrete: a software change whose intent, design, implementation and validation can be inspected together. That is the reason to consider Kiro for complex development work, and the standard against which its output can be evaluated.