Sappers DFIR

Weekly Threat Watch

September 21, 2026

2

MIN READ

Cisco ISE Zero-Day, TanStack Supply Chain Poisoning, and Feral Wolf Ransomware

A weekly threat watch detailing the Cisco ISE zero-day, TanStack supply chain attack, Linux LPE Quartet, Settra/Feral Wolf ransomware, and active edge exploitation.

Share this post

TABLE OF CONTENT

This week’s intelligence highlights an intense wave of structural zero-day exploitation, deep supply chain compromises, and evasive ransomware tactics. Threat actors are weaponizing edge network appliances for initial access, stealing developer OAuth tokens via poisoned dependencies to bypass MFA, and leveraging native OS components to execute destructive ransomware campaigns.

SISA Weekly Threat Watch – our weekly feature brings to you a quick snapshot of all the major security vulnerabilities that posed a threat to organizations worldwide. These recurring actionable threat advisories will also provide information and recommendations that will help security teams take appropriate actions to defend against the latest and critical threats.

1. Critical Edge & Perimeter Exploitation

Edge network appliances and perimeter firewalls are under active, critical bombardment from unauthenticated threat actors executing remote code and deploying persistent backdoors.

  • Cisco ISE Zero-Day & Check Point Root RCE — Active in-the-wild exploitation is targeting an authentication bypass (CVE-2026-76460, CVSS 10.0) in the Cisco Identity Services Engine (ISE) API Gateway, granting full administrative control. Simultaneously, Check Point Security Management servers face a critical stack-based buffer overflow (CVE-2026-91843) allowing remote, unauthenticated attackers to execute arbitrary code with root privileges.
  • Fortinet & Cisco Email Gateway Active Exploitation — Threat actors are actively weaponizing FortiOS SSL-VPNs (CVE-2024-21762) and Cisco Secure Email Gateways (CVE-2026-76461). In observed campaigns, attackers use these perimeter flaws for initial access, harvest credentials from RADIUS and MySQL databases, and deploy legitimate Remote Management Tools (MeshCentral) as persistent backdoors while wiping forensic logs.
  • Unbound DNSSEC Flaws & Docker Sandbox Escapes — NLnet Labs Unbound DNS resolved multiple high-severity flaws, including cross-zone wildcard cache poisoning and DNS-over-QUIC DoS. Additionally, critical symlink race conditions in Docker Sandboxes (CVE-2026-77179) allow malicious microVM guest workloads to escape and access host files.

2. Supply Chain Attacks & OS Privilege Escalation

Adversaries are poisoning upstream developer ecosystems to steal identities, while exploiting kernel-level memory safety flaws to achieve SYSTEM-level execution.

  • TanStack Supply Chain Attack (CVE-2026-45321) — A major supply chain attack compromised 42 @tanstack npm packages. Threat actors injected the "Shai Hulud" infostealer to harvest GitHub OAuth tokens, cloud credentials, and SSH keys directly from developer endpoints. This enabled the attackers to bypass MFA and secretly clone over 170 private repositories from downstream organizations.
  • Linux LPE Quartet — Four memory-safety vulnerabilities (DirtyAH6, TUNderflow, PPPoEject, DiagSpill) in the Linux kernel networking subsystems allow local low-privileged users to achieve root execution or DoS.
  • Apache Syncope & Oracle CSPU — Oracle released its massive September 2026 CSPU addressing over 800 vulnerabilities, including unauthenticated RCE flaws in Fusion Middleware and E-Business Suite. Additionally, Apache Syncope disclosed three flaws allowing unauthenticated SQL injection, Groovy sandbox escapes, and JWT token exposure.

3. Ransomware, Extortion & Defense Evasion

Extortion groups and espionage operations are bypassing EDR monitoring by deploying covert communication networks, Bring Your Own Vulnerable Driver (BYOVD) tactics, and living-off-the-land utilities.

  • Settra & Feral Wolf Ransomware — Settra leverages compromised VPNs, MeshAgent RMM, and BYOVD attacks (gdrv.sys) to disable endpoint protection before encrypting environments. Feral Wolf targets Atlassian Confluence, performs container escapes, extracts credentials offline using DumpIt, and communicates over MQTT and Matrix protocols before deploying GenieLocker.
  • Iran-Linked Handala Hack & SilkParasite Operations — Iranian threat actor Void Manticore is deploying a Python-based Telegram surveillance backdoor (HEAVYGRAM/CHOSEN BRICK) via a Delphi staging loader (CRUDEEXCLUDE). Concurrently, the SilkParasite espionage campaign targets Central Asia using SpiceRAT, leveraging domain spoofing and Chinese CA-issued TLS certificates.
  • KREMLIN, BambooToken & Noodle RAT — Advanced multi-vector operations are leveraging Ethereum smart contracts as C2 resolvers (KREMLIN), abusing Tendyron PKI software via MQTT C2s (BambooToken), and utilizing mature cross-platform RATs across APAC (Noodle RAT).

Proactive Steps for the Week

  • Apply Edge Infrastructure Patches Immediately: Patch Cisco ISE, Check Point Gateways, FortiOS, and Cisco Secure Email Gateways without delay. Isolate management interfaces from public access, ensuring they are only accessible via trusted internal administrative subnets.
  • Audit Open-Source Dependencies & Disable Lifecycle Scripts: Configure npm and yarn to disable automatic install-time execution of third-party scripts (npm config set ignore-scripts true) to neutralize the TanStack supply chain attack. Treat any endpoint that executed compromised packages as fully breached and rotate all local SSH keys, cloud API keys, and OAuth authorization tokens.
  • Deploy Core OS & Enterprise Updates: Apply updated Linux distribution kernels to mitigate the LPE Quartet flaws. Apply Oracle's September 2026 CSPU across affected enterprise components, patch Apache Syncope, and update Unbound DNS and Docker Desktop installations.
  • Harden Identity & Defend Against Ransomware: Enforce MFA on all external access portals to thwart initial access vectors used by Settra and Feral Wolf. Monitor for unauthorized RMM tools (MeshAgent) and memory dump utilities (DumpIt). Enable Hypervisor-Protected Code Integrity (HVCI) and driver blocklists to neutralize BYOVD attacks.
  • Monitor Cloud and C2 Infrastructure: Restrict network traffic to the Telegram API if not required for business operations to disrupt HEAVYGRAM. Block outbound MQTT proxy connections and monitor Web3 Ethereum RPC node queries to sever covert command-and-control channels.

Explore our DFIR Solutions to discover how our advanced incident response support, compromise assessments, and threat hunting frameworks can insulate your enterprise infrastructure against these campaigns.

SHARE THIS POST