Bharat Threat FeedGlobal threats, decoded for Indian defenders
Nirad Bharat Threat Feed

India-first threat intelligence

Global threats, decoded for Indian defenders — weekly briefs, sector editions, and AI Threat Watch. Every claim source-attributed.

Weekly Latest Weekly Brief 25 September 2026 Open issue →

Weekly Brief — 25 September 2026

September was a month of management-plane failures. Most of what follows is not a flaw in how a device forwards traffic, but in the console or orchestrator that authenticates administrators and holds credentials for everything behind it. For Indian teams running multi-branch estates, one unpatched controller exposes every device beneath it.
1

F5 BIG-IP APM pre-authentication remote code execution — CVE-2026-94127

India exposureBIG-IP APM fronts remote access for much of Indian banking, insurance and telecom. The risk applies where a virtual server carries an access policy with an OAuth profile or acts as an OAuth authorisation server, and F5 confirmed exploitation in the wild at disclosure.
ActionApply the hotfix for your train, or ask F5 Support for the interim iRule mitigation, then check OAuth authentication failures and TMM core files.
SourceF5 advisory, carried in CERT-EU advisory 2026-013, 22 September 2026; CISA Known Exploited Vulnerabilities catalogue, 22 September 2026.
2CriticalCVSS 10.0

Arista VeloCloud Orchestrator rated CVSS 10.0 and exploited before the fix — CVE-2026-93952

India exposureOn-premises VeloCloud Orchestrator runs SD-WAN for Indian enterprises and for providers managing customer branches. An attacker needs only network access to its web interface and the public part of an Edge certificate, and a compromised Orchestrator reaches every branch it configures.
ActionTrains 5.2, 6.1, 6.4 and 7.0 are affected, with fixes out for 5.2 and 6.4 first. Where none exists yet, take the web interface off untrusted networks.
SourceArista Security Advisory 0183, 22 September 2026; CISA KEV catalogue, 22 September 2026.
3

Check Point gateways and management servers under two separate attacks — CVE-2026-85102 and CVE-2026-93616

India exposureCVE-2026-85102 is pre-authentication code execution in VPN certificate validation, hitting Security Gateway and the Spark line that Indian mid-market firms and their service providers run. Check Point fixed it on 9 September and saw attempts against Spark customers from 12 September, none confirmed successful. CVE-2026-93616, a management-service path traversal, drew targeted attacks on 23 July.
ActionTreat these as two jobs. LivePatch covers the VPN flaw but not the management one, which Check Point says Take 28 and 29 leave open. Exact builds are in support notes sk1000117 and sk1000171.
SourceCheck Point security advisory, 22 September 2026; CISA KEV catalogue, 22 September 2026.
4CriticalCVSS 10.0

Cisco Secure Firewall Management Center worked by a state actor and a ransomware crew — CVE-2026-20079 and CVE-2026-20316

India exposureCVE-2026-20079 scores CVSS 10.0 and lets an unauthenticated attacker bypass the management web interface and run commands as root; CVE-2026-20316, a hard-coded credential flaw, chains with it. Talos is tracking three clusters: a financially motivated group using web shells, one linked to the Russian state actor Sandworm, and one tied to Qilin ransomware. Management Center sits above the firewall estate in Indian BFSI, manufacturing and government networks.
ActionApply the hardening release of 16 September and fixed builds, and take the interface off the internet. Rotate the credentials it holds, since patching does not undo earlier theft.
SourceBleepingComputer, 9 September 2026; Cisco Talos research reported by SecurityWeek, 10 September 2026; CISA KEV catalogue, 9 September 2026.
5CriticalCVSS 10.0

Adobe Commerce template injection exploited, rated critical by CERT-In — CVE-2026-75650

India exposureRated CVSS 10.0, it gives unauthenticated code execution through PHP smuggled in HTTP headers that runs when the platform renders automated email, and needs the /graphql endpoint reachable. Indian retail, direct-to-consumer brands and B2B distributors run Adobe Commerce and Magento Open Source widely, and staging instances are the weak point: internet-reachable, rarely patched on the storefront schedule.
ActionApply APSB26-146 alongside APSB26-138, enumerate every deployment including staging and QA, and confirm the version actually running rather than the change record.
SourceAdobe APSB26-146, 7 September 2026; Akamai Security Intelligence Group, 14 September 2026; CERT-In CIVN-2026-0458, 16 September 2026.
6

Fortinet CAPWAP flaw reaches the exploited catalogue eight months after its patch — CVE-2025-25249

India exposureA heap overflow in the CAPWAP daemon on UDP 5246 in FortiOS and FortiSwitchManager allows unauthenticated code execution. Fortinet patched it in January with no exploitation known then; CISA added it on 9 September. SOCRadar reports a campaign delivering PivotC2 since July, attributed to a financially motivated Russian-speaking group, with 178 compromised FortiGate devices from a target list above 30,000 still-unpatched addresses. FortiGate is among the most widely deployed firewalls in Indian networks.
ActionUpgrade, or remove fabric access from external interfaces and drop inbound UDP 5246 to 5249 with a local-in policy. Where PivotC2 artefacts appear, treat the configuration as exfiltrated.
SourceFortinet advisory FG-IR-25-084, 13 January 2026; SOCRadar research on the PivotC2 campaign; CISA KEV catalogue, 9 September 2026. In every item above the vulnerable component is the part of the estate administrators trust most and monitor least, and in four of them exploitation was already running when the fix went public. Patching closes the route in but settles nothing about what was taken while it stood open. For orchestrators and management consoles, credential rotation decides whether the intrusion ended. — Nirad Threat Research
Sector Latest Sector Edition September 2026 Open issue →

Government & Defence Sector Edition — September 2026

This month's government and defence exposure did not come from new malware. It came from the administrative machinery departments rarely count as security assets: the print server in the records room, the VPN appliance at the gateway, the virtualisation console in the data centre, the build repository the software vendor runs, and the remote-management platform the outsourced IT provider uses. Four of those were confirmed under exploitation in August, and a case in the Philippines showed what happens when a strategic research body leaves internet-facing software unpatched for two years.

1. Sector snapshot

The pattern across August 2026 is administrative planes reachable from places they should not be. Print and output management, edge VPN gateways, virtualisation management, MSP remote-management platforms and artefact repositories all saw confirmed exploitation, and in three cases exploitation preceded or outpaced the vendor fix. Against that, CERT-In spent June and July running ten customised exercises themed "Building Resilience against Frontier AI-driven Cyber Threats", drawing 1,470 participants from 345 government and private-sector organisations across power, telecom, BFSI, transport, education, healthcare and space. The gap this edition is concerned with sits between that exercise capability and the ordinary patch record on assets nobody in the security team owns.

Source (with date): MeitY and CERT-In, as reported by ANI (30 Jul 2026).

2. Threats targeting government & defence

PaperCut NG/MF: two flaws chained into unauthenticated code execution, exploited before the fix. CVE-2026-81578, an improper access control flaw in the web management interface, lets an unauthenticated attacker change configuration values that should require an administrator login. Chained with CVE-2026-82078, an unsafe dynamic class-loading flaw rated CVSS 9.4, it becomes arbitrary Java bytecode execution on the Application Server with no credentials and no user interaction. PaperCut published an urgent advisory on 27 August 2026 and confirmed customer incidents; the work came from Huntress, watchTowr and a university customer's security team. All NG and MF versions are affected. The first emergency patch was bypassed within about 48 hours and superseded by Emergency Patch Release 2, so take the current release from the vendor advisory rather than assuming the first fix held. Interim mitigation is restricting Application Server web access to trusted addresses. In Indian departments and PSUs this software usually sits with facilities or IT operations rather than security, which is why it is off the patch calendar.

Source (with date): PaperCut urgent advisory; Help Net Security (27 Aug 2026); CISA KEV (31 Aug 2026).

A strategic research body and a naval supplier, reached through flaws patched over two years ago. Hunt.io reported finding an exposed staging server holding attack scripts, logs written in Simplified Chinese, and data taken from two Philippine organisations. A nuclear research body was reached through CVE-2023-49105, an ownCloud WebDAV authentication bypass rated CVSS 9.8, disclosed in November 2023 and fixed in 10.13.1; the attacker abused pre-signed URLs with empty signing secrets to retrieve files without credentials. Roughly 176 files relating to nuclear research operations were taken, which we are not itemising. A second victim was a marine engineering firm supporting the Philippine Navy, reached through CVE-2024-28000, a LiteSpeed Cache WordPress plugin flaw allowing unauthenticated creation of an administrator account. Hunt.io stopped short of naming a state group, noting that language artefacts are among the easiest indicators to plant. India is not a victim here. It belongs in an Indian advisory because of the target shape: a defence-adjacent research institute and a naval supply-chain firm, both running internet-facing software years behind its fix, is a profile that exists across Indian strategic research and shipyard supplier estates.

Source (with date): Hunt.io; The Hacker News (28 Aug 2026); Security Affairs (29 Aug 2026).

VMware vCenter turned into root, then ransomware on the ESXi hosts underneath. CVE-2026-59310 is a directory traversal in the vCenter Syslog service rated CVSS 9.8, disclosed by Broadcom on 29 July 2026 with no workaround. QUIRSO assesses with moderate confidence that the campaign is run by a Chinese-speaking actor working in the UTC+08:00 time zone, based on language artefacts, tooling, working hours and a victimology excluding mainland China; no named group is claimed. Exploitation gave immediate root-context code execution. The actor wrote malformed files into /etc/cron.d, staged tooling through scheduled jobs, dropped reverse SSH binaries for persistence, and in at least one case deployed Babuk-derived ransomware on ESXi hosts, renaming partially encrypted files with a .babyk extension — read as partly a smokescreen, since encrypting ESXi logs removes the telemetry a defender needs. QUIRSO mapped 361 affected IP addresses across 47 countries, 343 of them by 5 August 2026, with technology, research, education and telecommunications environments among those exposed. One appliance was also hit through CVE-2026-59309, an authentication bypass. CISA listed the traversal flaw on 18 August 2026. vCenter 6.x and 7.x are past end of general support, and patching is not closure here; an exposed appliance needs a compromise assessment.

Source (with date): QUIRSO; The Hacker News (17 Aug 2026); CISA KEV (18 Aug 2026).

The standing Pakistan-nexus baseline has not moved. APT36 (Transparent Tribe) and the aligned SideCopy cluster remain the continuous espionage pressure on Indian government and defence networks, with cross-platform Windows and Linux RAT activity reported this year, including GETA RAT, ARES RAT and Desk RAT, and earlier CYFIRMA work on weaponised .desktop autostart files aimed at BOSS Linux desktops. Keep those detections live regardless of what else is in this issue.

Source (with date): Aryaka; The Hacker News (Feb 2026); CYFIRMA.

Insider risk, with a device-install element. Delhi Police and Air Force intelligence arrested an Indian Air Force officer on 31 May 2026 over alleged leakage of sensitive material to a suspected Pakistani handler contacted through social media. Reporting states the officer was also asked to install an application on a colleague's phone, treated by investigators as a suspected attempt to plant remote-access spyware. The officer has been booked under the Official Secrets Act and the extent of any compromise was still being assessed at the time of reporting. No individual is named here and nothing beyond the reported allegations should be assumed. The control point is narrow: on a defence estate, sideload blocking, device enrolment and alerting on peer-initiated installs are counter-espionage controls, not only device hygiene.

Source (with date): The Week (08 Aug 2026).

3. Sector tech & exposures

Citrix NetScaler ADC and Gateway, CVE-2026-8452. Citrix described this in June 2026 as a memory overflow capable of denial of service. watchTowr Labs published analysis and proof-of-concept code on 14 August 2026 showing it reaches unauthenticated remote code execution, and CISA listed it on 26 August 2026 with a 29 August federal remediation date. Observed activity includes web shells named x.php and z.php alongside discovery commands. It affects appliances configured for SSL VPN, ICA Proxy, CVPN, RDP Proxy or AAA virtual servers; take the fixed builds from the Citrix bulletin rather than secondary reporting. Second NetScaler item in two editions, same pattern: a memory-safety bug scoped down at disclosure, then reopened by outside research.

Source (with date): watchTowr Labs; Help Net Security (27 Aug 2026); CISA KEV (26 Aug 2026).

Cisco Secure Firewall ASA and FTD, CVE-2026-20349. CVSS 8.6. A single crafted HTTP request crashes and reloads the Remote Access SSL VPN service, an unauthenticated denial of service against the remote-access path itself. Cisco confirmed active exploitation on 11 August 2026 and CISA listed it the same day with a 14 August federal deadline. No public actor attribution, and it should not be conflated with the earlier ArcaneDoor espionage activity on the same product line.

Source (with date): Cisco; CISA KEV (11 Aug 2026).

N-able N-central, CVE-2026-18577. Authentication bypass and account takeover rated CVSS 8.2, an incomplete fix for CVE-2026-18556, affecting builds before 2026.3.1.7 across on-premises and cloud-hosted deployments. It surfaced on 31 July 2026 when N-able's own managed detection service found zero-day exploitation in a customer environment. Attackers then used the platform's Take Control feature to reach managed endpoints and installed Cloudflare Tunnel for persistence that survived revocation of N-central access. CISA listed it on 3 August 2026; a second hotfix followed on 6 August. Where a department's endpoint estate is run by an outsourced provider, that provider's management platform is part of the department's attack surface whether or not it appears on the asset register.

Source (with date): N-able; Rapid7; CISA KEV (03 Aug 2026).

JFrog Artifactory, CVE-2026-82329. Authentication bypass rated CVSS 9.8; in the default configuration an unauthenticated attacker with network access can obtain administrative privileges, which watchTowr traces to instances without an additional join key receiving a usable placeholder key. JFrog patched on 28 August 2026 across branches 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38 and 7.161.20. watchTowr reported observed exploitation on 1 September 2026: token minting, enumeration of users, groups and credentials, and in a small number of cases creation of backdoor accounts. Not yet on the KEV list at the time of that reporting. An artefact repository sits in the middle of a delivery pipeline, so for e-governance and defence software this is a supply-chain exposure, not a routine server patch.

Source (with date): JFrog; watchTowr; The Hacker News (01 Sep 2026).

SonicWall Global Management System. CVE-2026-66147, an unauthenticated command injection in the GMS Dispatcher Service rated CVSS 9.4, and CVE-2026-66145, rated 9.1, allowing an unauthenticated attacker to read sensitive data and write arbitrary files via zipslip. Both affect GMS 9.5.1 and earlier on the Virtual Appliance and Windows, fixed in 9.5.2, and the same advisory carries four further flaws. GMS was decommissioned in October 2025, which is precisely why lingering deployments deserve a check: a firewall fleet management server is a policy-rewrite position across every appliance it manages.

Source (with date): SonicWall PSIRT SNWLID-2026-0011; Center for Internet Security advisory 2026-083 (12 Aug 2026).

The identity plane, and a correction worth carrying. Microsoft's 20 August 2026 service update batch included CVE-2026-59115, a path-traversal elevation of privilege in the Entra Provisioning Service, and CVE-2026-50481 in Azure Active Directory, both rated CVSS 9.9. Separately, CVE-2026-69836, a deserialization remote code execution flaw in Entra ID rated CVSS 10.0, was first published with its "Exploited" field set to Yes; Microsoft corrected that to No on 21 August 2026, and as a managed service the fix was applied on Microsoft's own infrastructure with nothing for customers to install. Several outlets still carry the original framing, so a board paper citing an exploited CVSS 10.0 Entra flaw needs correcting.

Source (with date): Microsoft MSRC; Help Net Security (21 Aug 2026); SecurityWeek (24 Aug 2026).

4. Regulatory & compliance watch

CERT-In's patch expectation read against this month's list. The May 2026 AI-exploitation guidance, CISG-2026-02, sets an indicative expectation of 12 hours to contain or remediate known exploited vulnerabilities on internet-facing systems, one day for critical externally exposed flaws and five days for high-severity issues on a risk basis. It is guidance with indicative timelines, not a binding mandate, and it sits alongside the April 2022 directions requiring incident reporting within six hours, 180-day log retention within Indian jurisdiction and clock synchronisation to NPL. Read against sections 2 and 3, an internet-facing PaperCut server or a pre-fix NetScaler carried into September is well outside that window. Where systems are notified as protected systems under section 70A of the IT Act, NCIIPC's directions run in parallel with CERT-In's, and both clocks start together.

Source (with date): CERT-In; The Hacker News (26 May 2026).

MeitY's state cybersecurity framework process. MeitY is running a four-stage departmental summit process to build a national cybersecurity framework architecture covering all 36 states and union territories, following directions from the Prime Minister at the fifth National Conference of Chief Secretaries. The second stage was a national consultative workshop in New Delhi on 11 May 2026, after which states and union territories were asked to hold internal workshops and submit structured recommendations by 30 June 2026, with a National Departmental Summit scheduled for August 2026 to discuss the final framework. State IT and home departments should confirm where their own submission landed, because this process will set their baseline. The institutional split remains MeitY on IT Act matters, the Ministry of Home Affairs on cyber-crime, the National Security Council Secretariat on coordination, CERT-In as the section 70B incident agency and NCIIPC under NTRO for critical information infrastructure.

Source (with date): MeitY, as reported by Indian Television (17 May 2026).

A useful external benchmark: CISA's BOD 26-04. Issued on 10 June 2026, it supersedes and revokes BOD 19-02 and BOD 22-01, drops CVSS as the prioritisation basis, and requires a three-day fix where a flaw is publicly exposed, listed as known exploited, automatable and technically impactful. It also requires forensic triage to establish whether the affected system was already compromised, rather than treating a patch as the end of the matter. It binds United States federal civilian agencies only and has no force in India, but the structure is worth borrowing: exposure and exploitation status driving the clock, with compromise assessment written into the remediation step.

Source (with date): CISA (10 Jun 2026).

5. Actor in focus — UAT-10147

Cisco Talos published its analysis of UAT-10147 on 20 August 2026: a previously undocumented Chinese-speaking intrusion set, assessed as financially motivated rather than state-directed, active since early 2026 against vulnerable Windows and Linux web servers worldwide. Talos names government and education among the affected sectors, and Brazil, Bolivia, China, Canada and Vietnam among victim countries. India is not named in that reporting, and this is not an India-targeting campaign. It appears here for the operating model, not the victim list.

An operational security lapse exposed the actor's staging server, revealing a target list of roughly 170,000 URLs alongside AI-generated operational documentation and automation scripts. Talos assesses with moderate-to-high confidence that the actor uses agentic AI systems to run offensive tradecraft at scale, threading AI-driven tooling through exploitation, reconnaissance, payload generation, validation and persistence alongside conventional open-source frameworks. Initial access is entirely through publicly disclosed vulnerabilities in long-lived software: CVE-2022-27925 in Zimbra, CVE-2019-18935 in Telerik UI for ASP.NET AJAX, CVE-2021-23758 in Ajax.NET Professional, and CVE-2021-29441 and CVE-2021-29442 in Alibaba Nacos, followed by Linux privilege escalation through flaws dating back as far as 2010. On Windows it modifies Defender exclusions and creates scheduled tasks disguised as "Google Chrome Start"; on Linux it plants web shells and then escalates. A follow-on Talos report covers SPECTRE, a cross-platform implant with process injection, credential theft, a Linux rootkit and driver-based EDR bypass. Exfiltration is routed through a legitimate cloud configuration management service so it resembles ordinary administrative traffic. On 26 August 2026 CISA added four of the legacy flaws this actor uses to its exploited list.

The exposure for Indian government and PSU estates is real even without named Indian targeting. Automated, AI-assisted scanning for years-old unpatched internet-facing software is precisely the shape of a departmental web estate still carrying legacy Zimbra, Telerik and .NET components, often on domains inherited from a project that ended years ago. As always in this feed, India-nexus actors are out of scope; the lens is foreign activity that creates exposure for Indian organisations.

Source (with date): Cisco Talos (20 Aug 2026); The Hacker News (Aug 2026); CISA KEV (26 Aug 2026).

6. IOC pack

Every entry below is already public in the named source and is reproduced with attribution. These are not Nirad observations. The table mixes atomic indicators with behavioural detection leads; the Type column says which is which, and the leads need tuning against your own baseline.

IndicatorTypeContextSource
x.php, z.phpWeb shell filenamesNetScaler CVE-2026-8452 exploitationwatchTowr Labs
adminapi.tippusoni[.]inDomainUAT-10147 infrastructureCisco Talos
cloudflared service, unexplainedPersistence artefactN-able N-central post-exploitationN-able
svchost.exe inside a user's Documents folderMasqueraded binaryN-able N-central post-exploitationN-able
.babyk extension on ESXi datastoresRansomware artefactvCenter CVE-2026-59310 campaignQUIRSO
Files written to /etc/cron.d on a vCenter applianceDetection leadvCenter CVE-2026-59310 persistenceQUIRSO
Google Chrome Start scheduled taskDetection leadUAT-10147 persistenceCisco Talos
Anomalous child processes of pc-app.exeDetection leadPaperCut exploitationHuntress
Missing, truncated or deleted server.logDetection lead (anti-forensics)PaperCut exploitationPaperCut
ERROR No suitable driver found for jdbc:no:xLog stringPaperCut exploitationHelp Net Security
Snort SIDs 66696, 66697Detection signatureUAT-10147 activityCisco Talos
SPECTRE, NoodleRAT, QuasarRAT, Gh0stCringeMalware familiesUAT-10147 toolingCisco Talos
CVE-2026-81578, CVE-2026-82078CVE referencePaperCut chain, exploitedCISA KEV
CVE-2026-8452CVE referenceNetScaler, exploitedCISA KEV
CVE-2026-20349CVE referenceCisco ASA/FTD VPN denial of service, exploitedCISA KEV
CVE-2026-18577CVE referenceN-able N-central authentication bypass, exploitedCISA KEV
CVE-2026-59310, CVE-2026-59309CVE referencevCenter traversal and authentication bypassCISA KEV; QUIRSO
CVE-2026-82329CVE referenceJFrog Artifactory authentication bypasswatchTowr Labs
CVE-2023-49105, CVE-2024-28000CVE referenceownCloud and LiteSpeed Cache, Philippine casesHunt.io

7. Tiered actions

Board. Ask for a written position on internet-facing exposure across four asset classes usually missing from the departmental register: print and output management, edge VPN appliances, virtualisation management, and build or artefact repositories. Ask whether the outsourced IT provider's remote-management platform sits inside the department's own risk register, and who patches it. Ask whether the six-hour CERT-In reporting path has been tested end to end, including out of hours, and whether NCIIPC reporting runs in parallel for any notified protected system. Where the department funds a research institute or a defence-adjacent supplier, ask what their patch position is on internet-facing software.

CISO. Patch on an emergency basis across PaperCut, NetScaler, vCenter, Cisco ASA and FTD, N-able N-central and Artifactory; on PaperCut take the current emergency release, not the first one. Treat an exploited vCenter or Artifactory as compromised until an assessment says otherwise: rotate credentials, tokens and keys rather than only applying the fix, and check for administrative accounts and scheduled jobs created before the patch. Restrict PaperCut and vCenter management interfaces to trusted networks. Inventory internet-facing legacy software across the department and its funded institutes, specifically ownCloud, Zimbra, Telerik and WordPress plugin estates, including domains inherited from closed projects. Require managed service providers to report their own patch state. At the device management layer, block sideloaded packages on issued devices and alert on peer-initiated installs.

SOC. Hunt the indicators in section 6. On the perimeter, alert on new .php files in NetScaler web paths and on unexpected reloads of the ASA remote-access VPN service. In the data centre, alert on new or modified files in /etc/cron.d on vCenter appliances and on reverse SSH sessions from appliance addresses, and baseline vCenter and ESXi administrative logins now rather than during an incident. Across the estate, alert on unexplained cloudflared services and outbound tunnels, on Defender exclusion changes, on PaperCut server log gaps, and on Artifactory administrative token creation and user enumeration. Keep the APT36 lure paths and .desktop autostart detections in the active set.

8. Source index

ANI · Aryaka · Center for Internet Security · CERT-In (CISG-2026-02) · CISA · CISA KEV · Cisco · Cisco Talos · Citrix · CYFIRMA · Help Net Security · Hunt.io · Huntress · Indian Television · JFrog · MeitY · Microsoft MSRC · N-able · PaperCut · QUIRSO · Rapid7 · Security Affairs · SecurityWeek · SonicWall PSIRT · The Hacker News · The Week · watchTowr Labs

9. Byline

1

Nirad Threat Research

NBTF — Government & Defence Sector Edition | 2 September 2026

AI Watch Latest AI Threat Watch 24 September 2026 Open issue →

AI Threat Watch — 24 September 2026

Four disclosures in the past week, and in each one a control that teams assume is doing its job turns out not to be. A pinned plugin version that does not actually pin. An AI gateway that ships with its management authentication switched off. An approval prompt where the action a person reviewed is not the action that runs. And a European regulator logging a breach in which an agent, working from valid credentials, found the weakness and acted on it without anyone directing the intermediate steps. None of this is about models becoming cleverer. It is about the scaffolding around them being trusted more than it has earned.
1

A flaw named Plugin4Shell lets a plugin update run attacker-controlled code inside four widely used AI coding agents, and the version pin that was supposed to prevent this does not hold

The Air Security research lab published the finding on 17 September 2026, credited to Or Nevo, Dor Granat and Niv Hoffman. It concerns the plugin and extension mechanism in Claude Code, OpenAI Codex, GitHub Copilot and Google Gemini CLI. Developers pin a plugin to a reviewed commit identifier on the understanding that the code cannot then change underneath them. The researchers showed that the agents check out the pinned identifier but never confirm afterwards that the working tree actually landed on it, and that a repository reference whose name is a forty-character hexadecimal string can take precedence over the commit object of the same name. The pin reports success while different content is installed. It requires no click because Claude Code and Codex update installed plugins in the background by default, so the sequence is to publish something useful, wait for adoption, and change the upstream repository later. No CVE identifier was recorded at publication. Patch status as reported by the researchers: Anthropic fixed it in Claude Code 2.1.179 and OpenAI in Codex 0.146.0. Microsoft has not shipped a fix for GitHub Copilot. Google is not planning one for Gemini CLI, which it has deprecated in favour of Antigravity.

Why it matters for IndiaCoding agents are now standard issue in Indian product companies, GCC engineering functions and services firms working on client estates, and a plugin inherits whatever the developer running the agent holds. On a typical Indian engineering workstation that means source code, cloud credentials, SSH keys, CI tokens and, for services teams, access into a customer's environment rather than only your own. The research does not report exploitation, and no source describes Indian organisations being targeted. The exposure is structural: the reason teams allowed plugins at all was that pinning made the supply chain reviewable, and for two of these products that assurance is still not restored.
ActionUpgrade Claude Code to 2.1.179 and Codex to 0.146.0. For Copilot and Gemini CLI, where no fix is available, take the decision consciously rather than by default: disable automatic plugin updates, or restrict plugins to an internal allowlist, and record who accepted the risk. Find out whether your engineering teams have plugins installed at all, because in most organisations nobody is tracking this. Run coding agents without production credentials in the environment, and rotate anything an agent workstation has held.
SourceAir Security research lab, "Plugin4Shell" (17 September 2026); The Register (17 September 2026); Help Net Security (18 September 2026).
2

A critical flaw in the Bifrost AI gateway allows command execution with no credentials at all, and the authentication that would have stopped it is off by default

JFrog Security Research published CVE-2026-90898 on 14 September 2026, found by Yuval Moravchick, with wider reporting on 22 September. It is rated 9.8 and affects the Bifrost HTTP transport, maintained by Maxim, in all versions before 2.1.0. A single unauthenticated request to the management API can register a stdio-type client, at which point the gateway launches the specified command as its own process user, before any handshake takes place. The condition that makes this reachable is the shipped default, in which management authentication is disabled and every caller is treated as a local administrator. The stock binary binds the management API to localhost, which limits exposure, but the official Docker image binds to all interfaces, so the management API is reachable from outside the container wherever the port has been published. Check your version carefully: the 2.0.0 release fixed an earlier plugin issue, CVE-2026-86242, and does not block this one, and the 1.6.x line through 1.6.11 has neither fix. A separate batch of roughly twenty CVE identifiers was published on 22 September 2026 against sooperset/mcp-atlassian, the Model Context Protocol server that connects agents to Jira and Confluence, including CVE-2026-77254 at 9.1 for missing authentication on the HTTP endpoint and CVE-2026-77255 at 8.6, where the server can be made to read local files and attach them to an issue. The chronology is worth stating plainly, because it cuts both ways: the fix has been available in 0.22.0 since the upstream advisories of 10 July 2026, so this is a CVE assignment catching up rather than a new disclosure. Anyone who has not upgraded has been exposed for over two months.

Why it matters for IndiaAn LLM gateway is the one component that holds provider keys for every model an organisation uses, which is precisely why Indian banks, fintechs, telecom operators and GCC platform teams put one in front of their AI estate. Command execution on that process is access to the whole key set and to the traffic passing through it. The default-off authentication is the part to dwell on, because a team standing a gateway up for an internal pilot has no prompt telling them the control exists, and pilots in Indian organisations routinely reach production without anyone revisiting that. For a regulated entity, prompt and response traffic through that gateway is customer data under the Digital Personal Data Protection Act.
ActionUpgrade Bifrost to transports 2.1.0 or later, and do not treat 2.0.0 as sufficient. Upgrade mcp-atlassian to 0.22.0. Enable management authentication on every gateway you run and confirm the management listener is not published outside the host, checking that from another machine rather than from the configuration file. Where an instance ran with authentication disabled and the management API reachable, follow JFrog's guidance and treat it as compromised: rotate virtual keys and every provider credential it held. Then apply the general form of this to the rest of the estate, because agent and gateway control planes are the surface where authentication is most often available and least often switched on.
SourceJFrog Security Research, CVE-2026-90898, JFSA-2026-001686326 (14 September 2026); The Hacker News (22 September 2026); GitLab Advisory Database entries for CVE-2026-77254 and CVE-2026-77255, mcp-atlassian (22 September 2026), upstream GitHub advisories (10 July 2026).
3

Research published this week shows that a person can approve one agent action while a materially different one executes, which undermines the control most organisations are relying on

Adithyan Arun Kumar submitted a paper on 17 September 2026 describing what the author calls loopjacking. The structure is that a human approves what they understand to be operation A, and the implementation applies that approval to operation B. Two variants are set out: attacks on what the approval screen represents, where B is concealed at the point of review, and post-approval substitution, where the approved operation is replaced before it runs. Behaviour was demonstrated in Agno AgentOS through 3.0.9, in a tested LangGraph Agent Server configuration through 0.14.0, and in OpenClaw 2026.2.23, which was fixed in 2026.2.24. The OpenAI Agents SDK, at 0.22.0 and 0.22.2, rejected the attacks and served as a negative control in the study. These were purposive test cases and not a survey, so they do not establish how widespread the pattern is.

Why it matters for IndiaHuman-in-the-loop approval is the control Indian enterprises have leaned on hardest while putting agents into change management, ticket handling, payment operations, data exports and SOC automation. It is what appears in the risk register and what is shown to an auditor, and it is frequently the only thing standing between an agent and a consequential action. The finding does not say approval is worthless. It says the binding between what was shown and what executes has to be built deliberately, and in several frameworks it was not. That matters more here because a large share of Indian agent deployments are assembled by an integrator on top of one of these frameworks, so the property is inherited rather than chosen.
ActionFor each agent workflow with an approval step, establish what exactly is being approved and whether the executing component receives the same object the reviewer saw, or only a reference that can be re-read later. Ask your integrator this question in writing. Upgrade OpenClaw to 2026.2.24 or later. Log the approved action and the executed action separately and compare them, since a divergence is detectable even when it is not preventable. For high-consequence actions, put a control that does not depend on the agent's own reporting, such as a payment limit or a separate authorisation at the target system.
SourceAdithyan Arun Kumar, "Loopjacking", arXiv 2609.21081 (17 September 2026).
4

Spain's data protection authority has logged the first breach notification it has received in which the attack was carried out by an autonomous AI agent

The Agencia Española de Protección de Datos received the notification on 14 September 2026. Its account is that a third party used an AI agent as the instrument for chaining the phases of the attack: the agent logged in using valid credentials, searched the application for weaknesses on its own, then modified personal data and accessed invoices, with no human operator directing the intermediate steps. The regulator has not named the affected organisation, the model provider, the vulnerability or the number of people whose data was involved. The account comes from the breached organisation and remains under review, so treat the technical detail as provisional. What is not provisional is the procedural point: an agent-executed intrusion has now entered the GDPR Article 32 and 33 breach-notification machinery as a category a regulator has recorded. It is worth being precise about what failed. On the facts released, this was valid credentials plus application weaknesses that a patient attacker would also have found. The agent supplied the patience. The harder question it raises is about accountability: when an agent chains actions under legitimate credentials, the logs show authorised activity, and reconstructing intent afterwards is a different exercise from reading an audit trail.

Why it matters for IndiaTwo reasons, and the compliance one is the nearer. Indian IT services firms, GCCs and product companies process EU personal data for clients under contractual terms that inherit these obligations, so this is a notification standard their customers will now be measured against. The second reason is domestic. CERT-In's reporting requirements and the Digital Personal Data Protection Act both assume an organisation can explain what happened, and an intrusion conducted entirely through valid credentials at machine speed is hard to explain from access logs alone. We are not aware of public reporting of an equivalent case before an Indian regulator, and an absence of reporting should not be read as an absence of the activity. The gap to close is the ability to answer the question if it is asked.
ActionReview your detection for authenticated sessions rather than for failed logins, since this activity was authenticated throughout. Rate of action within a session is the signal available to you: a valid account enumerating an application and modifying records faster than a person works is visible in application logs if anyone is looking. Make sure application-layer logs capture what was changed and not only that access occurred. Check that your incident response plan can describe a sequence of authorised actions as an incident, because most plans are written around unauthorised access. For teams handling EU personal data, confirm your notification timeline holds when the initial account of the incident is incomplete, which is the situation here.
SourceAgencia Española de Protección de Datos, breach notification received 14 September 2026; SecurityWeek, reported by Kevin Townsend (16 September 2026); Spanish coverage 15 to 18 September 2026.
AI defender tip: Read these four together and the common element is not a missing control. It is a control that was present and was believed. The plugin pin returned success while installing something else. The gateway's authentication existed and was off in the shipped configuration. The approval prompt collected a decision and applied it elsewhere. The access logs in the Spanish case recorded legitimate activity throughout, accurately, and that is exactly the problem. Every one of these would pass a control questionnaire, because a questionnaire asks whether the control is in place and not whether it binds to the thing you think it binds to. The exercise for this week is narrow enough to finish. Take the three agent or AI systems your organisation actually runs, not the ones in the strategy deck. For each, name the single control you would cite if asked why it is safe, then verify that one control from outside the system: connect to the gateway from another machine without credentials and confirm it refuses you; compare an approval record against what the target system recorded as executed; check that a pinned dependency is the commit you reviewed. Most teams will find at least one control that reports success without doing the work, and the useful part is that this is a checkable question with an answer, which is more than can be said for most items on an AI risk register.

Nirad Threat Research

Nirad AI Threat Watch | Bharat-first threat intelligence