// 4 ZERO-DAY · 6 CVE · 10 EXPLOIT · 1 ADVISORY IN THE LAST 24H→
SENT ISSUE WEEKLY-2026-W39

DeafLetter — week 39

CISA Adds Three Linux Kernel CVEs to KEV With Three-Day Deadline for US Agencies

SNAPSHOT // IMMUTABLEEN
DEAFNEWS DEAFLETTER // SECURITY BRIEF
VERIFIED SIGNALS // EDITORIAL SNAPSHOT

DeafLetter — week 39

CISA Adds Three Linux Kernel CVEs to KEV With Three-Day Deadline for US Agencies

01 // LEAD STORY
LEAD // 01

CISA Adds Three Linux Kernel CVEs to KEV With Three-Day Deadline for US Agencies

CISA added three Linux kernel vulnerabilities to the Known Exploited Vulnerabilities catalog on September 18, 2026, giving federal civilian agencies until September 21 to patch. The directive is driven by confirmed active exploitation, not CVSS severity alone. Red Hat has flagged CVE-2025-39682 as high risk with public exploits available.

OPEN REPORT →
02 // THREE SIGNALS
SIGNAL // 02

CenterPoint Energy Confirms Data Breach: 7 Million Customers' PII at Risk

CenterPoint Energy filed an SEC Form 8-K on September 14, 2026, confirming a data breach in which an unauthorized actor accessed customer personal information through an external-facing system. The utility, serving roughly 7 million customers across Indiana, Minnesota, Ohio, and Texas, disclosed the incident after identifying a dark web post claiming the sale of stolen data. Electric and gas services were not disrupted, and no OT/SCADA impact has been identified.

READ THE ANALYSIS →
SIGNAL // 03

PhantomRaven: The npm Malware Likely Written by an LLM to Fuel Bug Bounty Fraud

CrowdStrike has exposed PhantomRaven, a JavaScript infostealer distributed via npm and likely generated with an LLM. The financially motivated actor poses as a bug bounty hunter on platforms like HackerOne, Bugcrowd, and Intigriti but uses stolen credentials to manufacture vulnerabilities for payout rather than selling data on criminal markets.

READ THE ANALYSIS →
SIGNAL // 04

CISA Confirms: CVE-2026-59310 in vCenter Now Exploited by Ransomware

The critical CVE-2026-59310 vulnerability in VMware vCenter, patched in July, has shifted from APT exploitation to ransomware attacks in a matter of weeks. CISA has flagged it as actively used in ransomware campaigns and mandated forensic triage under BOD 26-04.

READ THE ANALYSIS →
03 // CVES AND PATCHES
CVE_PATCH // 05

JADEPUFFER Encrypts AI Weights with ENCFORGE: Phantom Ransom, Broken Payment Mechanism

The agentic ransomware group JADEPUFFER struck Langflow infrastructure with ENCFORGE, a payload that encrypts AI models without a functioning ransom mechanism. Recovery costs for a single enterprise-ready fine-tuned model are estimated at $75,000–$500,000.

READ THE ANALYSIS →
CVE_PATCH // 06

Infected PHP Themes on Streaming Sites: The iOS Chain That Empties Crypto Wallets

Thirteen compromised Packagist packages turn Vietnamese streaming sites into vectors for a WebKit-to-kernel exploit chain on iPhone, stealing seed phrases from seven cryptocurrency wallets.

READ THE ANALYSIS →
CVE_PATCH // 07

Two Bugs in OpenAI Codex Break the Strictest Sandbox in Read-Only Mode

Oren Yomtov of Accomplish AI discovered and demonstrated two sandbox-escape vulnerabilities in OpenAI Codex — Heapjack and Overpatch — that allow unsandboxed command execution on the user's host machine, even in the most restrictive read-only mode. Both were reported on August 12, 2026 and patched by OpenAI within eight days.

READ THE ANALYSIS →
CVE_PATCH // 08

npm Package indexed-btree Evades Install-Time Defenses With Runtime Payload

The npm package indexed-btree, masquerading as the legitimate sorted-btree library and pulling nearly 2 million weekly downloads, hides its malicious payload inside the BTree.prototype.set() method. Execution triggers at runtime when the application calls the method, not during installation, bypassing npm v12's mandatory approval gates for install scripts introduced in June 2026. Checkmarx disclosed the campaign on September 20, 2026, revealing a first-stage obfuscated loader that harvests system details and communicates with a C2 orchestrated via an Ethereum smart contract on the Sepolia testnet. Nine additional npm packages linked to the operation have been removed from the registry.

READ THE ANALYSIS →
CVE_PATCH // 09

BragJack: A Malicious Extension Hijacks Five AI Agents in Chromium Browsers

A proof-of-concept demonstrates how a pre-installed malicious extension can control AI agents in Chrome, Edge, Opera, Perplexity, and Claude. Two CVEs assigned.

READ THE ANALYSIS →
04 // THE GUIDE
GUIDE // 10

Foundations of Ethical Security Testing with Python: A Beginner's Laboratory Guide

You have a terminal open and a fresh Kali ISO on your desktop, but no idea which command runs first—or whether that command is even legal. This guide is for that exact moment. We start from zero: installing Python, writing your first script, and understanding why a variable named `password` is not the same as a variable named `PASSWORD`. From there we build a vocabulary of defense—CIA triad, CVE, scope, responsible disclosure—and construct a legally isolated lab network we call Wintermute. Every attack category is taught from two angles: how it works conceptually, and how you would detect or block it. You will not find live exploit code against real targets here. You will find commented Python snippets, lab checklists, and the explicit requirement of written authorization before any technique leaves your virtual network. Sections 1–4 establish your toolkit and ground rules; Sections 5–9 walk network reconnaissance, web application flaws, DoS concepts, wireless and social vectors, and malware mechanics without executing dangerous payloads; Sections 10–11 consolidate everything into a capstone assessment and a troubleshooting reference for when your lab inevitably breaks. Read with a notebook, test only in machines you own, and treat every script as a defensive sensor in disguise. **What you need:** a laptop with 8 GB RAM, VirtualBox or VMware, and patience for your first syntax errors. **What you will not do:** run unmodified exploits against infrastructure you do not own.

READ THE ANALYSIS →
MANAGE PREFERENCES →
You receive this email because you subscribed to DeafLetter. Unsubscribe
Samuel — DeafNews · Privacy