TL;DR
Android banking trojans (Mantax Otax, Gigabud) now targeting Indonesia via obfuscation techniques; AI-powered campaign using hundreds of agents compromised 395 PaperCut NG/MF servers; Citrix, Fortinet, Chromium vulnerabilities actively exploited—federal remediation due September 12.
Executive Summary
- Android banking malware (Mantax Otax, Gigabud) exploits work profile features to evade detection and steal credentials in Indonesia and beyond.
- A likely Russian-speaking threat actor deployed hundreds of AI agents to automatically exploit PaperCut NG/MF flaws, compromising 395 organizations globally.
- Three critical vulnerabilities now listed on CISA's Known Exploited Vulnerabilities catalog with active in-the-wild attacks: Citrix NetScaler authentication bypass (CVE-2026-19490), Fortinet buffer overflow (CVE-2025-25249), and Chromium V8 out-of-bounds write (CVE-2026-87491).
- Microsoft September patch cycle included nearly 1,000 CVE fixes; Windows Server updates broke Remote Desktop Services on multiple versions. ⚠
- A researcher (Nightmare-Eclipse) published a zero-day Windows Defender exploit (CVE-2026-69414) as part of an ongoing vendetta against Microsoft.
Top Threats Today
1. AI-Powered PaperCut Exploitation Campaign
Severity: HIGH Affected: Technology
A threat actor, likely Russian-speaking, used hundreds of AI agents to develop and launch a global exploitation campaign targeting vulnerable PaperCut NG/MF servers ⚠ [1][2]. According to independent reports, the campaign compromised more than 395 organizations [2]. The attacker weaponized recently disclosed security flaws in PaperCut to achieve unauthorized access at scale. Attribution is based on language indicators and operational patterns; details of the specific vulnerabilities exploited remain limited in public disclosure [1].
Sources:[1] The Hacker News[2] BleepingComputer
Recommended Action
- Immediately patch PaperCut NG/MF to the latest available version; consult PaperCut security advisories for specific build numbers.
- Review access logs for PaperCut administrative consoles and API endpoints; isolate compromised instances pending incident investigation.
- Deploy network segmentation to restrict PaperCut server communications and limit lateral movement from compromised systems.
- Monitor for indicators of compromise (IOCs) released by Blackpoint Cyber and GreyNoise regarding this campaign.
2. Android Banking Trojans (Mantax Otax, Gigabud)
Severity: HIGH Affected: Finance
A new strain of Android malware called Mantax Otax combines ransomware and spyware functionality to encrypt files, steal sensitive data, and harass victims through spam and contact harassment [2]. Separately, the Gigabud banking trojan has evolved to install a second Android app that creates a work profile on compromised phones, allowing attackers to drop a tampered banking application inside the isolated work environment to evade banking app security checks [1][3]. The GoldFactory threat group is associated with the Gigabud campaign targeting Indonesia [3].
Sources:[1] The Hacker News[2] BleepingComputer[3] Dark Reading
Recommended Action
- Advise users to download banking apps only from official app stores and verify publisher identity before installation.
- Disable Google Play Early Access app installations at the organizational level if mobile device management (MDM) policies support it.
- Monitor corporate Android devices for unexpected work profiles or unfamiliar applications; use MDM tools to audit and restrict work profile creation.
- Recommend users enable Google Play Protect scanning and keep Android OS patches current.
3. Critical Vulnerabilities Added to CISA Known Exploited Vulnerabilities (KEV)
Severity: HIGH Affected: Technology
CISA added three critical vulnerabilities to its Known Exploited Vulnerabilities catalog on September 9, 2026, all with evidence of active exploitation: CVE-2026-19490 (Citrix NetScaler authentication bypass allowing unauthenticated remote code execution) [1], CVE-2025-25249 (Fortinet FortiOS, FortiSwitchManager, and FortiSASE heap-based buffer overflow enabling unauthorized code execution) [2], and CVE-2026-87491 (Google Chromium V8 out-of-bounds write affecting Chrome, Microsoft Edge, and Opera browsers) [3]. Federal remediation deadline for Citrix and Fortinet vulnerabilities is September 12, 2026 [1][2]. The Chromium V8 vulnerability deadline is September 23, 2026 [3].
Sources:[1] CISA KEV[2] CISA KEV[3] CISA KEV
Recommended Action
- Apply security patches to Citrix NetScaler ADC and NetScaler Gateway appliances immediately; verify AAA virtual server and Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) configurations after patching.
- Update Fortinet FortiOS, FortiSwitchManager, and FortiSASE to patched versions; monitor network traffic for anomalous exploitation attempts.
- Deploy browser updates for Chrome, Microsoft Edge, and Opera to patch CVE-2026-87491; enforce auto-update policies for corporate endpoints.
- Prioritize patching in federal and critical infrastructure environments due to CISA remediation deadlines.
4. Google Play Early Access Abused for Deceptive Android Apps
Severity: HIGH Affected: Technology
Bad actors are misusing Google Play's Early Access program to push thousands of deceptive applications that falsely claim to offer money, rewards, casino winnings, and premium content [1][2]. Early Access apps bypass standard Google Play review processes, allowing malicious developers to distribute apps under false pretenses. The scale of this abuse extends to thousands of deceptive applications currently available through the program [1].
Sources:[1] The Hacker News[2] SecurityWeek
Recommended Action
- Educate users about the risks of Early Access apps and recommend avoiding untested applications from unknown developers.
- Implement MDM policies to restrict Early Access app installation on corporate devices.
- Report suspicious or deceptive apps directly to Google Play's abuse reporting system.
- Monitor app usage logs for rapid installation cycles or unexpected data exfiltration patterns.
5. Windows Update Regression & Published Windows Defender Zero-Day
Severity: MEDIUM Affected: Technology
Windows admins report that the September 2026 security updates are causing Remote Desktop Services (RDS) failures on Windows Server 2019, 2022, and 2025, preventing user connections and in some cases requiring a hard reset [1]. Separately, Microsoft Excel users are experiencing broken copy-and-paste and formula-dragging operations following the KB5002914 Office security update; rolling back the update restores functionality [2]. Additionally, a researcher known as Nightmare-Eclipse published a zero-day exploit for Windows Defender (CVE-2026-69414, code-named “ShieldCrash”) as part of an ongoing vendetta against Microsoft [3].
Sources:[1] BleepingComputer[2] BleepingComputer[3] Dark Reading
Recommended Action
- Pause rollout of September Windows Server and Excel updates pending availability of corrected patches; prioritize lab testing before broad deployment.
- For systems already affected by RDS failures, roll back the September update or apply Microsoft's emergency hotfix if released.
- For Excel copy-paste issues, uninstall KB5002914 and defer re-deployment until a corrected version is available.
- Monitor Windows Defender for [exploitation unverified] leveraging CVE-2026-69414; escalate alerts for suspicious Defender tamper events.
Today’s Action Checklist
- ☐ URGENT (by Sept 12): Patch Citrix NetScaler (CVE-2026-19490) and Fortinet devices (CVE-2025-25249); verify authentication bypass mitigations in place.
- ☐ URGENT (by Sept 23): Deploy browser updates for Chrome, Edge, and Opera to address CVE-2026-87491 (Chromium V8).
- ☐ HIGH: Scan for and patch PaperCut NG/MF instances; review access logs for signs of compromise by AI-driven exploitation.
- ☐ HIGH: Assess corporate Android estate for Mantax Otax and Gigabud indicators; enforce work profile restrictions via MDM.
- ☐ MEDIUM: Defer or roll back Windows Server and Excel September updates; test corrected versions in lab before re-deployment.
- ☐ MEDIUM: Review IDScan breach notifications if organization uses third-party identity verification services; monitor for credential reuse attacks.