The indexed-btree runtime-evasion campaign from yesterday remains the day's biggest single threat and holds its critical rating. Three new developer-targeting campaigns landed on top of it, all exploiting the same trust surface: the tools engineers install without a second thought.
SentinelOne ties Jade Sleet to a fresh IT-provider breach via FLATROOF and ROOFDECK, a joint advisory pins the Contagious Interview cluster to 30,000 compromised devices and $10.71M in stolen crypto, and a fake LastPass Authenticator installer on GitHub uses a Microsoft-signed kernel driver to blind AV and EDR before dropping a stealer — the same GitHub-as-dropper TTP flagged in yesterday's writeup. Separately, nginx-ignition picked up three disclosures in one batch: an unauthenticated admin-creation race, a ~75x CPU-amplification bug in its Accept-Language parsing, and TOTP reuse. CISA also added a Zyxel GS1900 switch buffer overflow to KEV today, an unauthenticated LAN-based OS-command flaw with a 72-hour remediation clock. The bright spot: every new disclosure today — nginx-ignition's three bugs and the carried-over Hatchet OAuth CSRF — already ships a patched version, so tonight is a patching problem, not a research gap.
→ Operational priority for the night patch nginx-ignition past the fix commit if you self-host it, remediate the Zyxel GS1900 KEV entry before its September 24 due date, and add indexed-btree and the fake LastPass installer's driver hash to EDR blocklists before end of day.