September 11, 2026 by sig9
Hacker Wars - September 11, 2026
Your daily dose of infosec chaos
DevOps infrastructure, print servers, and even keyboard input methods are all having a bad day. Attackers are chaining flaws in build pipelines to plant backdoors, AI is now writing exploits for print management software, and a Chinese APT found a home in an input method editor. Sprinkle in a crypto wallet phishing wave and one Conti operator heading to prison, and you have today’s menu.
Attackers Chain JFrog Flaws To Backdoor Build Pipelines
Wiz caught attackers chaining two flaws in self-hosted JFrog Artifactory servers to grab admin control and plant backdoors between mid-August and early September. Artifactory is the pantry your build pipelines pull from, so whoever owns it owns every artifact, token, and artifact consumer downstream.
What to do: Patch Artifactory, rotate every credential it stores, and verify artifact checksums before trusting anything built in the last month.
PaperCut Falls To AI-Powered Attack Campaign
A Russian threat actor used AI assistance to build, test, and fire exploits against two PaperCut flaws across hundreds of organizations, and PaperCut has now shipped proper maintenance releases to replace its emergency patches. Turns out AI is a perfectly competent junior exploit developer, minus the salary and the remorse.
What to do: Get to PaperCut NG/MF 26.0.5, 25.0.13, or 24.1.1, and assume any exposed instance was probed.
Chinese APT Hides Backdoor In Sogou Input Method Flaw
The China-linked UNC3569 group exploited a flaw in Sogou Input Method, one of the most popular tools for typing Chinese on Windows, to deploy its GRAYRABBIT backdoor via a single crafted link. When your keyboard software becomes an attack surface, the definition of “trusted endpoint” gets philosophical fast.
What to do: Audit any Windows fleet running Sogou IME, treat it as a legacy risk, and check for GRAYRABBIT persistence markers.
Brevo Breach Fuels Phishing Blitz On 347,000 Trezor Users
The marketing platform Brevo got breached, and attackers used its mailing infrastructure to hit 347,000 Trezor customers with convincing fake wallet-update emails - about 2,500 people clicked. Attackers no longer spoof your vendor’s domain, they just borrow the vendor’s actual email provider.
What to do: Treat unsolicited security emails as hostile, verify via the official site, and remind users that hardware wallets never ask for seed phrases.
Conti Ransomware Operator Gets Four Years
A Ukrainian national was sentenced to four years in prison for his role in Conti ransomware operations between 2021 and 2022. The gang is long gone, but the sentence is a reminder that these crews keep HR records too - and one leaky internal chat can turn into a court exhibit years later.
What to do: Keep law enforcement engagement in your IR playbook; attribution has a longer shelf life than most gangs.
That’s the chaos for today. Stay sharp out there.
Brought to you by sig9 - sig9.ch | Protecting the unseen, securing the unknown
This bulletin is provided for informational purposes. Contact us for tailored security analysis.