Sep 15: ScreenConnect Worm, Revolut Breach, GrayRabbit
ConnectWise patches CVE-2026-84869 (CVSS 9.9) in active worm-like attacks; Revolut breach via government impersonation; GrayRabbit deployed via Sogou flaw.
- CVE-2026-84869 (ConnectWise ScreenConnect, CVSS 9.9): exploited in worm-like attacks since at least August 20. ScreenConnect 26.6.5 shipped September 14 patching the flaw. CISA KEV federal deadline: September 14. If you haven't patched, patch now or disable TransferFiles permission as interim mitigation.
- Revolut breach confirmed September 14: threat actor impersonated a government agency via a valid official domain, obtained passport copies, KYC selfies, IBAN numbers, and full transaction history. No system compromise involved. Number of affected customers undisclosed. Revolut describes exposure as 'very limited.'
- CVE-2026-31278 (Suprema BioStar 2, CVSS 7.7 HIGH): unauthenticated API endpoint exposes Active Directory service account credentials. Affects BioStar 2 before 2.9.12 and BioStar X before 1.0.2. Patch and rotate the AD service account.
- GrayRabbit backdoor deployments via chained flaw in Tencent Sogou Input Method for Windows, attributed to China-aligned UNC3569. Patch to v16.3.0.3498 (released April 21, 2026) or remove Sogou from endpoints where it is not required.
Federal patch deadline expired. Active exploitation ongoing.
ScreenConnect CVE-2026-84869: deadline gone, worm active
CVE-2026-84869 (CVSS 9.9, critical). ConnectWise released ScreenConnect 26.6.5 on September 14 to close the flaw. CISA KEV federal remediation deadline: September 14. That deadline passed yesterday.
Exploitation documented since August 20. Huntress research describes the mechanic: attackers social-engineer targets into running rogue ScreenConnect client instances. The rogue client scans for other active sessions on the same host, then pushes four VBScript payloads through those sessions targeting persistence and lateral spread. The spread pattern Huntress calls worm-like: one compromised session creates attack vectors across connected endpoints.
Attribution: none confirmed. Scope of affected organizations: not publicly quantified.
ScreenConnect 26.6.5 patches the underlying flaw. If the update has not been deployed: disable the TransferFiles permission in ScreenConnect to remove the file-delivery vector.
Revolut breach: government impersonation, KYC data exposed
Revolut disclosed September 14 that a threat actor impersonated a government agency using email from a valid official government domain. Revolut’s internal process fulfilled the data request, believing it was legitimate. No technical vulnerability was exploited.
Data confirmed exposed: full name, date of birth, occupation, postal address, email, phone number, passport and driver’s license copies from KYC verification, facial verification selfies, IBAN numbers, and complete transaction history including Bitcoin transactions.
Scope: undisclosed. Revolut characterizes the exposure as “very limited.” Crypto investigator ZachXBT assessed the campaign as targeted at high-net-worth users. Confidence on that characterization: unconfirmed, treat accordingly.
Revolut accounts and funds were not accessed. Identity documents, KYC records, and transaction history were. The distinction matters: those records create risk for identity fraud and financial targeting regardless of account balance impact.
BioStar 2 CVE-2026-31278: AD credentials via unauthenticated API
CVE-2026-31278 (CVSS 7.7, HIGH). An unauthenticated API endpoint in Suprema BioStar 2 returns the Active Directory service account credentials stored by the platform. Any attacker with network access to the BioStar server can retrieve those credentials without authenticating.
Affected: BioStar 2 before version 2.9.12, BioStar X before 1.0.2. Patch to the fixed versions and rotate the AD service account. If the service account had broad AD privileges, scope that investigation accordingly.
GrayRabbit: UNC3569 targeting Sogou deployments
China-aligned UNC3569 is deploying the GrayRabbit backdoor through a chained flaw in Tencent Sogou Input Method for Windows. Gen Threat Labs published research; BleepingComputer covered it September 13.
Three weaknesses chained: the sgbiz: URI handler passes user-controlled arguments without validation, an embedded Chromium-based browser component navigates to arbitrary URLs, and the underlying Chromium 80 engine runs without a sandbox. Tencent patched the URI handler in version 16.3.0.3498 (released April 21, 2026). The embedded browser component remains outdated.
GrayRabbit capabilities: process execution, interactive reverse shell, file upload and download, system enumeration, in-memory plugin loading.
Mitigation: update Sogou Input Method to v16.3.0.3498 or later. Audit endpoints for Sogou presence, particularly in environments where it would not ordinarily be expected.
Also on the board
- CVSS 10 WordPress payment plugin CVE-2026-81648: unauthenticated privilege escalation to admin in a payment gateway plugin. Patch immediately if running the affected versions.
- BlueMoon exploit kit (Sep 13): Chrome renderer plus Windows privilege escalation chain used by espionage actors. Attribution to espionage-aligned threat cluster.
- Check Point VPN (Sep 13): Dutch NCSC warned of imminent exploitation of CVE-2026-85102 and CVE-2026-85103. Both are RCE flaws with active exploitation reported.
- 0dayNews — ScreenConnect Worm Attacks: CVE-2026-84869 Now Patched
- 0dayNews — Revolut Breach Exposes Passports and Financial Data
- 0dayNews — BioStar 2 API Leaks Active Directory Credentials
- 0dayNews — China-Linked UNC3569 Deploys GrayRabbit via Sogou Flaw
- SecurityWeek — ConnectWise patches ScreenConnect vulnerability
- BleepingComputer — Revolut discloses data breach