Cisco Nexus Root RCE and a Worm at 469 Locations (09/03/2026)
- › Cisco patched a critical flaw in 10 Silicon One-based Nexus 9000 switches that lets an unauthenticated remote attacker execute code as root.
- › GitGuardian found a Shai-Hulud worm variant scanning 469 separate credential locations across developer environments, build pipelines, and cloud configuration.
- › Attackers compromised Coder's Cloudflare infrastructure and stood up registry servers that served Terraform modules carrying credential-stealing code.
- › HPE patched a critical remote code execution flaw in the ArubaOS-CX network operating system.
- › Symantec reported attackers using the trusted Node.js runtime itself as the delivery mechanism for malicious payloads.
Four hundred and sixty-nine is the number worth carrying out of today. That is how many separate places one worm variant now knows to look for a credential on a developer’s machine, and it tells you what the current economics reward: an exhaustive map of where people leave secrets lying around, researched once and reused against everybody.
Top 5 Critical Security Alerts
1. Cisco Patches Unauthenticated Root Execution in Nexus 9000 Switches
Cisco released patches for a critical flaw affecting 10 Silicon One-based Nexus 9000 switches that allows an unauthenticated remote attacker to execute code as root, and shipped an IOS XR hardening release bundling seven CVEs alongside it. A data center switch running attacker code as root is not a compromised host, because it sits underneath every host and sees traffic between all of them. Anything you built on the assumption that east-west traffic stays inside your fabric depends on this device behaving. The Hacker News has the advisory detail.
Operator Note: Switch firmware falls outside most patch programs because it has no endpoint agent reporting on it, so check who owns this asset class before you check the version.
2. Shai-Hulud Now Scans 469 Credential Locations
GitGuardian researchers found in early August that a Shai-Hulud infostealer worm variant had evolved to scan 469 locations across developer environments, continuous integration and continuous deployment tooling, and cloud configuration files. The interesting part is the breadth rather than the technique, because 469 locations is somebody’s research output turned into a checklist. Every path on that list exists because a real developer on a real team left something there. The Hacker News breaks down what the expansion covers.
Operator Note: You cannot out-discipline a 469-item list, so the control that works is short-lived credentials that expire before the worm gets to sell them.
3. Coder’s Registry Served Malicious Terraform Modules
Attackers compromised Coder’s Cloudflare infrastructure and added unauthorized registry servers that delivered Terraform modules containing credential-stealing code. Infrastructure-as-code modules run with the permissions needed to build infrastructure, which is the highest privilege most organizations hand to anything, and they run in the pipeline where nobody is watching a screen. A malicious module does not need persistence when it gets executed on every apply. BleepingComputer has the timeline.
4. HPE Patches Critical ArubaOS-CX Remote Code Execution Flaw
Hewlett Packard Enterprise patched a critical vulnerability in the ArubaOS-CX network operating system that can lead to remote code execution. Two vendors shipping critical network operating system fixes on the same day is a scheduling coincidence, and the exposure it creates is not, because most organizations patch switches on an annual cycle if they patch them at all. The window between disclosure and your next maintenance weekend is the whole risk. BleepingComputer has the details.
5. Attackers Use the Node.js Runtime as the Delivery Mechanism
The Symantec Threat Hunter Team reported attackers using the trusted Node.js JavaScript runtime to deploy malicious payloads in targeted attacks. Node.js is signed, expected on developer and build machines, and allowlisted almost everywhere it appears, which means the execution itself generates no signal worth alerting on. Detection here has to come from what the process does afterward. The Hacker News has the report summary.
Additional Security Alerts
Threat Intelligence
- US becomes the top target in a remote monitoring and management phishing campaign: A campaign first thought to be aimed at Canada through Canada Revenue Agency tax form lures turned out to span 46 countries, with around 45% of observed activity now associated with the US. The Hacker News
- BraZetsu turns compromised Windows hosts into marketplace inventory: Researchers detailed a Python-based Windows malware framework that commercializes access to compromised machines through an underground marketplace, going beyond the standard infostealer model. The Hacker News
- AI agents compressed a two-week attack into 10 hours: Researchers documented an incident in which frontier AI agents coordinated a large-scale breach compressing a timeline that would normally run to two weeks of human effort. Dark Reading
Security Breaches and Incidents
- Thomson Reuters court software breach may have exposed sealed records: An unauthorized party obtained files from C-Track, the court case management platform sold by the West Publishing Corporation unit, in March 2026, affecting courts in 11 US states, the US Virgin Islands, and Ontario. Social Security numbers and sealed data may be involved. The Hacker News
- A proof of concept exploit for CrowdStrike Falcon is public: A researcher known for Microsoft zero-day work published working exploit code against the endpoint agent, which is software with kernel access on a very large number of machines. The Register
Emerging Security Technologies
- ASCII smuggling moves from prompt injection to email filter evasion: Invisible Unicode characters popularized for hiding instructions from AI models are now being used to obfuscate words before email security filters parse them. Microsoft Security
The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.
Operating on the philosophy that 'you can't build a secure system if you don't know how to break it,' Chris leads our engineering division. A top 1% National Cyber League competitor, he hardens our digital infrastructure against the very exploits he has mastered.
View Profile →Media Inquiries
For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.