September 14, 2026 Emerging Threats Weekly

Sep 15, 2026

This week’s briefing covers:

00:00 – Intro

00:54 [MALWARE] PEEP Turns Chrome and Edge into Persistent Post-exploitation Agents
Researchers identified PEEP as an emerging Chromium-based post-exploitation toolkit disguised as a browser extension named “Smart Bookmarks.” It is not an initial-access mechanism and instead requires prior administrative or code-execution access to turn Chrome or Edge into a persistent collection and command platform.

03:00 [AI] DeepSeek Harness Sandbox Bypass Enables Prompt-to-Host Compromise
CVE-2026-82533 is a critical vulnerability in DeepSeek Harness, DeepSeek's open-source AI coding-agent tool, that allowed a sandboxed coding agent to disable its own confinement and run commands on the developer workstation without further confirmation. OX Security demonstrated the flaw on the product's default configuration and assigned it a CVSS score of 9.4.

05:22 [MALWARE] BraZetsu Commercializes Corporate Access for Criminal Buyers
BraZetsu is an emerging Python-based Windows malware framework supporting an access-as-a-service marketplace rather than a standard steal-and-exit infostealer model. Researchers attribute the framework, with high confidence, to the Brazilian actor Exilware and reports targeting across e-commerce, corporate, financial, industrial and law-enforcement sectors, particularly in Brazil, with additional reach into Portugal, Spain, Argentina and Paraguay.

07:47 [VULNERABILITY] BlueMoon Exploit Kit Rapidly Adopted in Espionage Campaigns
Researchers disclosed a new browser-based exploit kit, BlueMoon, that was already in operational use by at least four espionage-motivated clusters within days of its first observed deployment in late August. Proofpoint has not established how the actors obtained the kit, although the rapid adoption indicates that the capability was shared privately or supplied through a common source.

10:56 [VULNERABILITY] Cisco FMC Flaws Chained for Espionage and Ransomware
Cisco Talos is tracking active exploitation of two vulnerabilities in on-premises Cisco Secure Firewall Management Center. CVE-2026-20079 is a critical authentication bypass with a CVSS score of 10.0 that can give an unauthenticated remote attacker root access, while CVE-2026-20316 exposes a static low-privileged account and can be combined with other FMC vulnerabilities to elevate privileges.

14:03 [VULNERABILITY] Adobe Commerce Vulnerability Under Active Exploitation
CERT-FR warned on September 8 that Adobe Commerce, Adobe Commerce B2B and Magento Open Source are affected by CVE-2026-75650, a critical vulnerability that can lead to arbitrary code execution. Adobe has confirmed exploitation in the wild and assigned the flaw a CVSS score of 10.0.

Dive deeper:

Kroll’s Monthly Threat Intelligence Spotlight Report: https://www.kroll.com/en/reports/cyber/threat-intelligence-reports/cti-spotlight-trends-report

Kroll’s Cyber Threat Intelligence: https://www.kroll.com/en/services/cyber/threat-intelligence-services

Kroll’s 2025 Cyber Threat Landscape Report: Cybercrime in the Crypto Era: https://www.kroll.com/Reports/Cyber/Threat-Intelligence-Reports/Threat-Landscape-Report-Lens-on-Crypto

Playlist of Kroll's Weekly Cyber Threat Intelligence Briefings: https://www.youtube.com/playlist

Kroll Cyber Blog: https://www.kroll.com/en/insights/cyber

Kroll Threat Intelligence Reports: https://www.kroll.com/en/reports/cyber/threat-intelligence-reports

Kroll Cyber and Data Resilience: https://www.kroll.com/en/services/cyber

#krollcyber #threatintelligence #cyberthreats