UNCLASSIFIED

Cyber Watch

2026-W38 · 14 Sep – 20 Sep 2026
Makani Lab · Cyber Watch
Operations · Force Protection · Professionals
BLUF — A five-nation advisory tied the WaterPlum fake-recruiter campaign to the DPRK 313 General Bureau: 30,000+ devices in 100+ countries, $10.71M stolen. CISA added Cisco Secure Email Gateway CVE-2026-76461 to KEV on disclosure day. AAFES is investigating suspicious messages pushed to military customers through its own channels.

Last 7 days by lane · 225 items

Operations 147Force Protection 44Space & Cyber Professionals 34

Categories

Vulns & exploits
109
Malware & tooling
45
Policy & guidance
36
Breach & leaked data
32
Space & SATCOM
25

Rising terms · 7d vs prior

ransomware119 (+115.3)AI44 (+30.3)Qilin19 (+18.1)Cisco17 (+13.7)energy16 (+12.7)

By the numbers

Known Exploited Vulnerabilities (KEV) added 6 (0 ransomware-linked) · leak-site victims 111 (42 PACOM AOR)

Leak-site victims by country · 30d

US
32
??
11
DE
8
BR
6
CA
6

Threat actor spotlight — WaterPlum · DPRK (313 General Bureau, Munitions Industry Department) · Contagious Interview, DeceptiveDevelopment, Famous Chollima (overlap), CL-STA-0240

Why now
An 18 Sep FBI/DC3 advisory with Japan, Australia, and Germany named WaterPlum a DPRK state campaign: 30,000+ devices, $10.71M stolen, and Japan's first laptop farm dismantled.
Mentions, 30d
7 this week
PACOM relevance
Japan is a primary target; the campaign hunts IT talent across Japan and the ROK.
Notable TTPs
  • Fake AI/crypto recruiters targeting developers
  • Weaponized GitHub 'coding assignment' repos
  • RATs and stealers for credentials and wallets
Countermeasures
  • Run interview code only in a disposable VM
  • Assume credential theft; rotate and enforce MFA
  • Alert on egress to non-standard package registries

OperationsThreats to networks, missions, and infrastructure the command depends on: exploited vulns, intrusions, APT campaigns, ICS/OT, SATCOM/PNT, telecom.

CyberScoop · 2026-09-18
A five-nation advisory attributed WaterPlum (Contagious Interview) to the DPRK 313 General Bureau.
So what: 30,000+ devices in 100+ countries and $10.71M from 7,000+ wallets; the lure also harvests credentials and IDs.
Consider: Consider warning technical staff and job-hunting families never to run interview code.
PACOMNORTHCOMAPT & espionageSocial engineeringWaterPlum
CISA Known Exploited Vulnerabilities · 2026-09-13
CISA added Cisco Secure Email Gateway CVE-2026-76461 (CVSS 9.8) to KEV the day Cisco disclosed it.
So what: Per Rapid7, a crafted email gives root command execution pre-authentication on an internet-facing gateway.
Consider: Recommend confirming with the S6 that Secure Email Gateway and ISE are patched.
GLOBALvulnerability_exploitationedge_device
UNCLASSIFIED · open-source reporting only · 5 sources · built 2026-09-20 17:36 HSTCyber Watch · 2026-W38 · page 1 of 2

UNCLASSIFIED

Force ProtectionWhat Guardians, Airmen, civilians, and families need to know personally: scams, social engineering, apps and devices, OPSEC, breaches of consumer services, official guidance.

DefenseScoop · 2026-09-18
AAFES is investigating suspicious messages sent to military customers via its official email and the My Exchange app, including a fake 'AAFES Security Team' wish-list link. It has not said whether a breach occurred.
So what: It came through a channel Guardians and families are trained to trust; AAFES serves ~30M shoppers.
Consider: Recommend telling families to delete the message and verify by calling AAFES support.
NORTHCOMPACOMScams & fraudSocial engineering
The Register — security · 2026-09-18
FBI IC3 reports law-enforcement and government impersonation scams have cost victims over $1.6B across ~61,000 complaints since January 2025, averaging more than $26,000 each.
So what: Rank, unit, and duty status are easy to research, and a fake police caller carries extra weight.
Consider: Be aware no agency or court demands payment by phone, gift card, wire, or crypto.
NORTHCOMScams & fraud
The Register — security · 2026-09-16
Google disclosed CVE-2026-58704, an improper authorization flaw in Pixel cellular modems exploitable with no user interaction, and warned of limited targeted exploitation. CISA added it to KEV the next day.
So what: A personal-device risk needing no user mistake; targeted spyware follows people, not networks.
Consider: Recommend Pixel users apply the September update; careful browsing does not mitigate zero-click.
GLOBALmobile_devicevulnerability_exploitation

Space & Cyber ProfessionalsContext for the cyber and space workforce: strategy, doctrine, policy, organization, workforce, standards, exercises, industry and technology trends.

U.S. Space Force · 2026-09-15
Secretary of the Air Force Troy Meink announced on-orbit space control weapons at the 2026 Air, Space and Cyber Conference, saying both services must defeat AI-enabled threats inside a slower budget process.
So what: An on-orbit space control mission raises the value of SPACEPAC ground stations as targets.
Consider: Recommend reviewing how S36 priorities map to the supporting ground segment.
GLOBALspace_policystrategy
DefenseScoop · 2026-09-16
Chairman of the Joint Chiefs Gen. Dan Caine said U.S. forces must assume they will be 'hunted by autonomous systems, jammed across the spectrum, and tracked in real time,' citing Ukrainian FPV drones using AI vision.
So what: Autonomy that survives GPS denial shifts the burden onto space-based PNT and comms resilience.
Consider: Recommend reviewing how resilience planning handles PNT-degraded threats.
GLOBALEUCOMstrategyai_security

Watch list

  • KEV due: Linux kernel 21 Sep, Windows 22 Sep, V8 23 Sep.
  • JFrog Artifactory KEV entries due 25 Sep.
  • Whether AAFES confirms a breach at the Exchange.

Recommendations (for awareness)

  • Confirm Cisco Secure Email Gateway and ISE are patched.
  • Push the AAFES warning to families: delete, verify by phone.
  • Pixel users: apply the September update (CVE-2026-58704).
UNCLASSIFIED · open-source reporting only · 5 sources · built 2026-09-20 17:36 HSTCyber Watch · 2026-W38 · page 2 of 2