BLUF — A five-nation advisory tied the WaterPlum fake-recruiter campaign to the DPRK 313 General Bureau: 30,000+ devices in 100+ countries, $10.71M stolen. CISA added Cisco Secure Email Gateway CVE-2026-76461 to KEV on disclosure day. AAFES is investigating suspicious messages pushed to military customers through its own channels.
Threat actor spotlight — WaterPlum · DPRK (313 General Bureau, Munitions Industry Department) · Contagious Interview, DeceptiveDevelopment, Famous Chollima (overlap), CL-STA-0240
Why now
An 18 Sep FBI/DC3 advisory with Japan, Australia, and Germany named WaterPlum a DPRK state campaign: 30,000+ devices, $10.71M stolen, and Japan's first laptop farm dismantled.
Mentions, 30d
7 this week
PACOM relevance
Japan is a primary target; the campaign hunts IT talent across Japan and the ROK.
Notable TTPs
Fake AI/crypto recruiters targeting developers
Weaponized GitHub 'coding assignment' repos
RATs and stealers for credentials and wallets
Countermeasures
Run interview code only in a disposable VM
Assume credential theft; rotate and enforce MFA
Alert on egress to non-standard package registries
OperationsThreats to networks, missions, and infrastructure the command depends on: exploited vulns, intrusions, APT campaigns, ICS/OT, SATCOM/PNT, telecom.
CISA added Cisco Secure Email Gateway CVE-2026-76461 (CVSS 9.8) to KEV the day Cisco disclosed it.
So what: Per Rapid7, a crafted email gives root command execution pre-authentication on an internet-facing gateway.
Consider: Recommend confirming with the S6 that Secure Email Gateway and ISE are patched.
GLOBALvulnerability_exploitationedge_device
UNCLASSIFIED · open-source reporting only · 5 sources · built 2026-09-20 17:36 HSTCyber Watch · 2026-W38 · page 1 of 2
UNCLASSIFIED
Force ProtectionWhat Guardians, Airmen, civilians, and families need to know personally: scams, social engineering, apps and devices, OPSEC, breaches of consumer services, official guidance.
AAFES is investigating suspicious messages sent to military customers via its official email and the My Exchange app, including a fake 'AAFES Security Team' wish-list link. It has not said whether a breach occurred.
So what: It came through a channel Guardians and families are trained to trust; AAFES serves ~30M shoppers.
Consider: Recommend telling families to delete the message and verify by calling AAFES support.
FBI IC3 reports law-enforcement and government impersonation scams have cost victims over $1.6B across ~61,000 complaints since January 2025, averaging more than $26,000 each.
So what: Rank, unit, and duty status are easy to research, and a fake police caller carries extra weight.
Consider: Be aware no agency or court demands payment by phone, gift card, wire, or crypto.
Google disclosed CVE-2026-58704, an improper authorization flaw in Pixel cellular modems exploitable with no user interaction, and warned of limited targeted exploitation. CISA added it to KEV the next day.
So what: A personal-device risk needing no user mistake; targeted spyware follows people, not networks.
Consider: Recommend Pixel users apply the September update; careful browsing does not mitigate zero-click.
GLOBALmobile_devicevulnerability_exploitation
Space & Cyber ProfessionalsContext for the cyber and space workforce: strategy, doctrine, policy, organization, workforce, standards, exercises, industry and technology trends.
Secretary of the Air Force Troy Meink announced on-orbit space control weapons at the 2026 Air, Space and Cyber Conference, saying both services must defeat AI-enabled threats inside a slower budget process.
So what: An on-orbit space control mission raises the value of SPACEPAC ground stations as targets.
Consider: Recommend reviewing how S36 priorities map to the supporting ground segment.
Chairman of the Joint Chiefs Gen. Dan Caine said U.S. forces must assume they will be 'hunted by autonomous systems, jammed across the spectrum, and tracked in real time,' citing Ukrainian FPV drones using AI vision.
So what: Autonomy that survives GPS denial shifts the burden onto space-based PNT and comms resilience.
Consider: Recommend reviewing how resilience planning handles PNT-degraded threats.
GLOBALEUCOMstrategyai_security
Watch list
KEV due: Linux kernel 21 Sep, Windows 22 Sep, V8 23 Sep.
JFrog Artifactory KEV entries due 25 Sep.
Whether AAFES confirms a breach at the Exchange.
Recommendations (for awareness)
Confirm Cisco Secure Email Gateway and ISE are patched.
Push the AAFES warning to families: delete, verify by phone.
Pixel users: apply the September update (CVE-2026-58704).
UNCLASSIFIED · open-source reporting only · 5 sources · built 2026-09-20 17:36 HSTCyber Watch · 2026-W38 · page 2 of 2