TABLE OF CONTENT
This week’s intelligence highlights an aggressive pivot by threat actors targeting core routing infrastructure, developer ecosystems, and edge security appliances. Adversaries are hijacking BGP routes to deploy malicious updates, weaponizing technical coding challenges to distribute cross-platform RATs, and heavily leveraging AI to enhance evasive spyware and stealth backdoors.
SISA Weekly Threat Watch – our weekly feature brings to you a quick snapshot of all the major security vulnerabilities that posed a threat to organizations worldwide. These recurring actionable threat advisories will also provide information and recommendations that will help security teams take appropriate actions to defend against the latest and critical threats.
1. Edge Appliances, Routing & Core Infrastructure
Threat actors are executing high-impact attacks against underlying network infrastructure, utilizing zero-days and protocol manipulation to bypass standard perimeter security.
- Virtualizor BGP Hijacking — In a highly sophisticated attack, adversaries are leveraging Border Gateway Protocol (BGP) hijacking to intercept network traffic destined for Virtualizor infrastructure. By manipulating BGP routes, the attackers seamlessly redirect administrative traffic to malicious servers, delivering trojanized software updates directly to virtualization management panels.
- SonicWall SMA1000 Zero-Days (SNWLID-2026-0016) — Multiple zero-day vulnerabilities in SonicWall SMA1000 series appliances are undergoing active exploitation in the wild. Attackers are leveraging these unpatched flaws to bypass authentication and achieve remote execution, gaining unconstrained access to internal enterprise networks.
- Cisco Nexus 9000 & IOS XR Critical RCE — Critical remote code execution vulnerabilities have been disclosed affecting Cisco Silicon One-based Nexus 9000 series switches and IOS XR software. These flaws allow attackers to execute arbitrary code at the network core, prompting Cisco to issue a major software hardening release.
2. Supply Chain & Developer Ecosystem Targeting
Advanced persistent threats (APTs) are aggressively targeting software developers and open-source supply chains to achieve stealthy initial access.
- Mirage Kitten Developer Challenges — The Mirage Kitten threat group is targeting software engineers by distributing trojanized developer challenges and technical interviews. These malicious coding tests silently deploy the cross-platform NodeRabbit and PollCat Remote Access Trojans (RATs), compromising developer workstations across multiple operating systems.
- npm Supply Chain Compromise (Trinitite Campaign) — A malicious supply-chain campaign successfully compromised the
@7nohe/openapi-react-query-codegenpackage. Utilizing the Mini Shai-Hulud malware variant (part of the Trinitite campaign), the poisoned package executes malicious scripts during the build process, compromising downstream applications and CI/CD pipelines.
3. Advanced Malware, AI-Assisted Spyware, and Stealth C2
Malware authors are increasingly utilizing trusted runtimes and AI assistance to upgrade information stealers and obfuscate command-and-control (C2) channels.
- Dual-Vector Node.js & AI-Assisted NodeStealer — Threat actors are abusing trusted, signed Node.js runtimes to bypass endpoint execution restrictions. This dual-vector campaign delivers an upgraded, AI-assisted version of Python NodeStealer spyware, which autonomously identifies and extracts high-value authentication tokens and financial data.
- Emerging Stealth Backdoors (TED, BraZetsu, and Toy Ghouls) — A new wave of evasive backdoors features AI-enhanced access frameworks and novel C2 communication channels. These implants utilize dynamic, machine-learning-driven evasion techniques to bypass network heuristics and establish deeply persistent footholds.
- REVSTEALER Information Stealer — A rapidly proliferating information stealer has emerged with a highly modular payload architecture, allowing operators to dynamically push new extraction modules targeting modern browser storage, cryptocurrency wallets, and local password managers.
4. Privilege Escalation & State-Sponsored Operations
State-sponsored clusters are utilizing deep OS-level memory corruption and systematic targeting to escalate privileges and maintain access to critical endpoints.
- China-Nexus Enterprise Targeting — A coordinated escalation in China-nexus cyber operations has been observed, systematically targeting enterprise endpoints and core network infrastructure to establish long-term espionage footholds.
- Zero-Days in Security Products & Display Drivers — Multiple zero-day memory corruption and privilege escalation vulnerabilities have been discovered affecting enterprise security agents and local display drivers. Attackers are exploiting these deep-system flaws to bypass Protected Process Light (PPL) controls and elevate standard user privileges to
SYSTEM.
Proactive Steps for the Week
- Monitor BGP Routes and Virtualization Infrastructure: Implement BGP route monitoring (e.g., RPKI validation) to detect unauthorized route announcements and hijack attempts targeting Virtualizor or other core management infrastructure. Ensure software updates are verified via cryptographic signatures, not just TLS transport.
- Secure Developer Workflows: Mandate that all technical assessments, coding challenges, and untrusted repositories be executed exclusively within isolated, ephemeral sandboxes or virtual machines to neutralize the Mirage Kitten (NodeRabbit/PollCat) threat vector.
- Audit Open-Source Dependencies: Immediately audit projects utilizing
@7nohe/openapi-react-query-codegenfor signs of the Mini Shai-Hulud variant. Pin dependencies to known-safe hashes and employ Software Composition Analysis (SCA) to detect anomalous build-script behaviors. - Patch Edge & Core Routing Hardware: Apply the latest firmware updates and Cisco IOS XR software hardening releases to mitigate the Nexus 9000 RCE flaws. Isolate SonicWall SMA1000 series appliances and apply the emergency hotfixes associated with SNWLID-2026-0016 to halt active zero-day exploitation.
- Restrict Trusted Runtime Abuse: Implement Application Control (WDAC/AppLocker) to strictly govern the execution of portable or locally dropped
node.exeand Python runtimes to prevent the dual-vector deployment of AI-assisted NodeStealer spyware.
Explore our DFIR Solutions to discover how our advanced incident response support, compromise assessments, and threat hunting frameworks can insulate your enterprise infrastructure against these campaigns.
.png)