The Daily Zero-Day

Date: SEPTEMBER 26, 2026 Editor-in-Chief: Jose Laurentino III Global Threat Intelligence Edition

Executive Summary

Today's intelligence briefing for September 26, 2026, highlights a rapidly evolving threat landscape heavily influenced by autonomous AI payloads, sophisticated malware delivery vectors, and widespread data exposure events. Key incidents include the resurgence of compromised GitHub Actions executing the Mini Shai-Hulud malware, the discovery of the first reported autonomous AI C2 implant (CLOSEDQUORUM), and an escalation in macOS targeting via PamStealer's server-side payload decryption. Concurrently, organizations face infrastructure-wide vulnerabilities ranging from ServiceNow's AI platform flaws to a massive student loan breach exposing 2.5 million records, emphasizing the critical need for resilient access controls, advanced forensic readiness, and proactive multi-factor authentication enforcement.

Top Intelligence Briefings

Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware

Two actions-cool GitHub Actions have been disabled for a second time after the repositories became accessible last week, months after they were initially compromised. This resurgence underscores the ongoing threat of persistent supply chain vectors executing malicious payloads like Mini Shai-Hulud.

Actionable Takeaway: Audit third-party GitHub Actions and pin action references to immutable commit hashes to prevent unexpected execution of re-enabled or hijacked repositories.

The Closed Quorum: Inside the First Reported Autonomous AI C2 Implant

Discovered through Cisco Talos’ CAIRN project, the CLOSEDQUORUM malware binary exhibits fully autonomous command and control (C2), marking a paradigm shift in how malware handles operational decision-making without human operator oversight. This aligns with broader concerns regarding AI sandbox escapes and autonomous agent risks.

Actionable Takeaway: Implement strict behavioral egress filtering and forensic readiness protocols to detect unusual autonomous outbound traffic patterns and isolate sandbox breaches immediately.

PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence

Cybersecurity researchers have flagged a new version of PamStealer that ensures its primary payload can only be recovered using live, server-side C2 decryption, complicating traditional static analysis and threat detection mechanisms on macOS endpoints.

Actionable Takeaway: Enhance endpoint monitoring on macOS assets to catch behavioral anomalies during runtime execution and block unauthorized outbound C2 staging requests.

U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions

A U.S. Army soldier who pleaded guilty to hacking multiple major telecommunications companies and illicitly stealing mobile call and text metadata for thousands of individuals has been sentenced to 70 months in federal prison.

Actionable Takeaway: Enforce strict internal privilege management, continuous session monitoring, and robust anomaly detection to mitigate insider access risks across critical telecom infrastructure.

Sources & References

Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware
https://thehackernews.com/2026/09/compromised-github-actions-came-back.html

PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence
https://thehackernews.com/2026/09/pamstealer-macos-malware-adds-live-c2.html

U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions
https://krebsonsecurity.com/2026/09/u-s-soldier-gets-70-months-in-prison-for-att-verizon-extortions/

Data Broker Radaris Loses Domains in Privacy Fight
https://krebsonsecurity.com/2026/09/data-broker-radaris-loses-domains-in-privacy-fight/

Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee
https://www.schneier.com/blog/archives/2026/09/friday-squid-blogging-participatory-squid-dissection-in-october-in-tennessee.html

On Anthropic’s AI Misuse Report
https://www.schneier.com/blog/archives/2026/09/on-anthropics-ai-misuse-report.html

AI Sandbox Escapes: Why Forensic Readiness Matters More Than Containment
https://www.darkreading.com/cyberattacks-data-breaches/ai-sandbox-escapes-forensic-readiness

What We Missed: Google Gemini Joins the AI Escape Party
https://www.darkreading.com/cyber-risk/what-we-missed-google-gemini-ai-escape-party

Student Loan Breach Exposes 2.5M Records
https://threatpost.com/student-loan-breach-exposes-2-5m-records/180492/

Watering Hole Attacks Push ScanBox Keylogger
https://threatpost.com/watering-hole-attacks-push-scanbox-keylogger/180490/

Is that vibe coded app safe? 5 checks before you download
https://www.welivesecurity.com/en/mobile-security/is-new-vibe-coded-app-safe-5-questions-ask-first/

Been told to pay at a Bitcoin ATM? Read this first
https://www.welivesecurity.com/en/scams/been-told-pay-bitcoin-atm-read-first/

Trust and the enticing consultancy offer
https://blog.talosintelligence.com/trust-and-the-enticing-consultancy-offer/

The Closed Quorum: Inside the first reported autonomous AI C2 implant
https://blog.talosintelligence.com/the-closed-quorum-inside-the-first-reported-autonomous-ai-c2-implant/

LinkedIn adds new checks for fake profiles and work histories
https://www.malwarebytes.com/blog/news/2026/09/linkedin-adds-new-checks-for-fake-profiles-and-work-histories

Kothamine malware uses Tailscale’s tailcat to evade network detection
https://www.malwarebytes.com/blog/threat-intel/2026/09/kothamine-malware-uses-tailscales-tailcat-to-evade-network-detection

LimeLeads - 17,838,396 breached accounts
https://haveibeenpwned.com/Breach/LimeLeads

Burger King Russia - 3,155,792 breached accounts
https://haveibeenpwned.com/Breach/BurgerKingRussia

A Closer Look at Malware From the Macfinger ClickFix Campaign, (Fri, Sep 25th)
https://isc.sans.edu/diary/rss/33368

ISC Stormcast For Friday, September 25th, 2026
https://isc.sans.edu/podcastdetail/10110

ICYMI: August 2026 @AWS Security
https://aws.amazon.com/blogs/security/icymi-august-2026-aws-security/

Supporting ASD’s multi-factor authentication campaign: Why MFA matters more than ever
https://aws.amazon.com/blogs/security/supporting-asds-multi-factor-authentication-campaign-why-mfa-matters-more-than-ever/

Cofense Expands AI-Driven Phishing Defense Platform to Advance Secure Behavior Management
https://cofense.com/blog/cofense-expands-ai-driven-phishing-defense-platform-to-advance-secure-behavior-management

Beyond Human Risk: A Better Way to Build Secure Behavior
https://cofense.com/blog/beyond-human-risk-a-better-way-to-build-secure-behavior

Ransom & Dark Web Issues Week 4, September 2026
https://asec.ahnlab.com/en/95545/

August 2026 Infostealer Trend Report
https://asec.ahnlab.com/en/95519/

Fake Xeno Roblox Cheats Deliver Powerful Java Stealer Through Discord and Forums
https://www.bitdefender.com/en-us/blog/labs/fake-xeno-roblox-discord-executor

Fake shops target shoppers across Europe with fake Samsung deals, counterfeit goods and World Cup scams
https://www.bitdefender.com/en-us/blog/labs/fake-shops-europe-samsung-world-cup-scams

UN Reports Citing Citizen Lab Submissions Published
https://citizenlab.ca/un-reports-citing-citizen-lab-submissions-published/

Submission to the Immigration and Refugee Board of Canada
https://citizenlab.ca/submission-to-the-immigration-and-refugee-board-of-canada/

Vulnerability in WEBCON BPS software (CVE-2026-92419)
https://cert.pl/en/posts/2026/09/CVE-2026-92419/

Inside a multi stage toll fraud operation targeting Poland
https://cert.pl/en/posts/2026/09/tollfraud-analysis/

CIS Community Defense Model v3.0: Turning Threat Intelligence Into Action
https://www.cisecurity.org/insights/blog/cis-community-defense-model-v3-turning-threat-intelligence-into-action

CIS Benchmarks September 2026 Update
https://www.cisecurity.org/insights/blog/cis-benchmarks-september-2026-update

Multiple Vulnerabilities in ServiceNow's AI Platform Could Allow for Unauthorized Access
https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-servicenows-ai-platform-could-allow-for-unauthorized-access_2026-102

Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution
https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-google-chrome-could-allow-for-arbitrary-code-execution_2026-101

Previous editions:
Fort Lauderdale, FL, September 28, 2026
Visitors since September 18th, 2026: 34,869