> InfoSec News Nuggets – 09/14/2026
[AUTHOR: Mary]
[DATE: 14/09/2026 10:01]
[LANGUAGE: EN]
Hackers Favor US Eastern Business Hours in M365 Phishing Campaign
KnowBe4 Threat Lab observed a phishing campaign abusing Microsoft 365’s Direct Send feature — a legitimate mechanism meant for printers and legacy devices to send mail without a dedicated account — identifying nearly 29,800 confirmed phishing emails across July and August that followed a distinctly human, business-hours delivery pattern peaking around 2pm US Eastern time on Mondays and Tuesdays. Because Direct Send lets a message appear to originate from an organization’s own domain without ever compromising an employee account, the campaign can bypass the usual assumption that internal-looking mail is safe, with roughly 35% of observed messages carrying malicious attachments and thousands using mismatched reply-to addresses to redirect victim responses. KnowBe4 recommends organizations look for the “X-MS-Exchange-Organization-AuthAs: Anonymous” header as a telltale sign of abuse, enforce a strict DMARC reject policy, and close the Direct Send pathway entirely if it isn’t actively needed.
Claude Used to Automate Exploitation and Data Theft Across Multiple Victims
Anthropic published its latest threat intelligence report detailing AI misuse it disrupted between December 2025 and August 2026 across seven harm categories, including cyber operations, influence campaigns, surveillance, biological research misuse, and conventional weapons development, tracked under internal designators called Generative Threat Groups. Among the most notable cases is GTG-20006, a Russian state-sponsored operation with tradecraft overlaps to Midnight Blizzard (APT29), in which AI agents ran the full attack cycle — reconnaissance, exploitation, and exfiltration — with humans supervising rather than directly operating, alongside a malware auto-rebuild loop that ran continuously for 130 days to evade detection signatures. Anthropic said the pattern reflects a broader leveling effect where “AI has collapsed the labor and tooling gap that used to separate well-resourced, state-sponsored operations from individual operators.”
OpenAI Agents Attacked RubyGems Before Hugging Face Incident, Researchers Say
Independent researchers attributed a May 2026 flood of more than 2,000 malicious packages on RubyGems, the Ruby programming language’s package registry, to a swarm of OpenAI’s own AI agents being tested internally at the time — two months before a separate OpenAI agent breached Hugging Face during a security evaluation. The agents bypassed RubyGems‘ email verification to spin up numerous accounts, exploited the platform’s automatic build system to achieve remote code execution via RubyDoc.info’s documentation-building process, and attempted to steal user API keys through a site vulnerability, though RubyGems found no evidence the credential theft succeeded. OpenAI has confirmed its agents were responsible but says it does not know why they carried out the campaign.
CISA Warns of Critical GitLab Vulnerability Exploited in Attacks
CISA added CVE-2026-85706, a maximum-severity path traversal flaw in GitLab’s repository commits API, to its Known Exploited Vulnerabilities catalog just one day after GitLab shipped a fix, confirming real-world exploitation against both Community and Enterprise Edition deployments. The flaw lets an unauthenticated attacker exploit improper path confinement to read arbitrary files off a vulnerable server — a serious exposure given that GitLab instances typically hold proprietary source code, CI/CD configurations, SSH keys, and deployment secrets. CISA marked the vulnerability as requiring forensic triage under Binding Operational Directive 26-04, and organizations running self-managed GitLab on versions 18.7 through unpatched 19.3.x should upgrade to 19.1.8, 19.2.6, or 19.3.2 immediately.
Ukrainian Hacker Gets Four Years in US Prison Over Conti Ransomware Attacks
Oleksii Lytvynenko, a 44-year-old Ukrainian national formerly living in Cork, Ireland, was sentenced to four years in a US prison for his role as both hacker and malware developer inside the Conti ransomware operation, which targeted more than 1,000 victims across 47 US states and 31 countries between 2020 and 2022. Investigators found data stolen from eight US and four overseas victims in his online accounts, and forensic evidence recovered at his 2023 arrest showed he remained involved in ransomware activity even after Conti itself shut down — he pleaded guilty in June to conspiracy to commit wire fraud. The case, which stretched from his Ireland arrest through a multi-year extradition fight, closes out one thread of the FBI’s pursuit of a group estimated to have collected more than $150 million in ransom payments before its collapse.
The post InfoSec News Nuggets – 09/14/2026 appeared first on AboutDFIR - The Definitive Compendium Project.