CyberSecurity.PH #048
North Korean hackers stole USD 388M from Bitget. ShinyHunters compromised the cybercrime leak site, risking secondary extortion. Ad-blocker browser extension exposed as spyware. Apple patched 260+ flaws, while a critical Cisco SD-WAN zero-day faces active exploitation.
CyberSecurity.PH is now supported by the PSA Intelligence Cyber Risks
APAC and Philippines
Suspected North Korean Threat Actors Stole USD 388 million in Cryptocurrency Using Stolen Backend Authority
Cryptocurrency exchange platform Bitget disclosed that a suspected North Korean threat actor group managed to steal USD 387.5 million (PHP 24.37 trillion) worth of cryptocurrency. Bitget stated that threat actors exploited a flaw within the platform to trigger fraudulent withdrawals without obtaining private keys.
The reported entry point was a vulnerability in a third-party security product. Bitget stated that attackers stole internal network credentials, accessed privileged backend systems, and inserted forged withdrawal instructions that bypassed verification. It reported that while hot and warm wallets were affected, private keys were not compromised and cold wallets were unaffected. These remain initial company findings pending a full public technical report.
Bitget’s Chief Executive attributed the attack to North Korean operators based primarily on attack and network patterns. PSA Intelligence further assesses that a North Korean Advanced Persistent Threat (APT) group tied to Lazarus is the most likely culprit due to the scale and sophistication of the attack. Moreover, analysts point out that it fits the operational pattern of North Korea’s Cyber Strategy, leveraging cryptocurrency as a vital economic resource for sustaining the North Korean state.
Impacted blockchains include Ethereum, XRP Ledger, Zcash, Tron, Arbitrum, Optimism, Base, BNB Smart Chain, Avalanche, Algorand, and Celestia.
PSA Intelligence notes that this incident highlights the evolving nature of threats against cryptocurrency. While the decentralized nature of blockchain architecture makes it highly resilient and tamper-resistant against common attacks, this incident indicates that hot and warm wallets in cryptocurrency exchanges remain vulnerable to cyber threat actors.
Cybersecurity Threat Landscape
Cybercrime Feud Between ShinyHunters and Clop Risks Collateral Damage over Past Extortion Victims
In September 2026, cybercrime group ShinyHunters targeted Russian-speaking ransomware group Clop’s data leak site. ShinyHunters exploited an unauthenticated file upload and traversal vulnerability, identified as Common Vulnerabilities and Exposures (CVE) 2026-42608, within Grav, the leak site’s content management system (CMS). ShinyHunters claimed to have exfiltrated the site’s source code, Grav plugins, system logs, and private keys.

The infighting between these two cybercrime groups can be traced back to 2025, when Clop ran an extortion campaign targeting the Oracle E-Business Suite (EBS) vulnerability (CVE-2025-61882). ShinyHunters alleges that Clop used an exploit that originally belonged to them without permission, and that someone from Clop threatened a ShinyHunters member.
While both groups have actively claimed victims in the Asia-Pacific region, including the Philippines, the attacks usually stem from global supply chain incidents rather than isolated local targeting, as evidenced by the recent Canvas breach in May 2026.
PSA Intelligence notes that this incident creates an unpredictable threat landscape where collateral damage can spill over into past victims. Companies that quietly paid Clop’s ransom demands to avoid public exposure are now at risk as ShinyHunters threatened to release information regarding which companies paid Clop, how much they paid, and to what Bitcoin addresses. This means that a resolved incident in the past can become an active incident again, as ransomware groups have a reputation for keeping data in some form even after a ransom has been paid.
This infighting in the cybercrime ecosystem also demonstrates that even malicious threat actor groups are subject to the same vulnerabilities they exploit in organizations.
PSA Intelligence highlights that paying threat actors their ransom demands offers no guarantee of data security, as threat actors frequently archive stolen information or don’t return the data at all. Cybersecurity professionals strongly advise against yielding to extortion demands as this continues to fund the ransomware industry and marks your organization as a lucrative target, increasing the likelihood of a future attack.
Cyber Risks to Monitor
Browser Extension Risks: ‘Poper Blocker’ Spyware Evades Security Checks Across Millions of Devices
Cybersecurity researchers from Bay Area Lab published a report revealing that “Poper Blocker” — a well-known and widely distributed browser extension marketed as an ad and pop-up blocker — is actually an advanced infostealer spyware. Once installed, the spyware silently downloads malicious payloads from remote servers. In the Chrome Web Store, the extension has over 2 million active users, a 4.8-star rating across over 80,000 reviews, and Google’s official “Featured” and “Established Publisher” badges, giving a sense of security and legitimacy when looking for a potential ad or pop-up blocker to use.

The extension is available in three different browsers: Google Chrome, Microsoft Edge, and Apple Safari. Browser availability and extension IDs include:
- Google Chrome: Distributed via the Chrome Web Store (bkkbcggnhapdmkeljlodobbkopceiche)
- Microsoft Edge: Distributed via Microsoft Edge Add-ons (baplddocidbpmmneofgnhkjojmibmpck)
- Apple Safari: Distributed via the Mac App Store/Safari Extensions (id6743758947)
Coerced Opt-In and Privacy Policy Loopholes
Once installed, the extension relies on “coerced consent” to manipulate users into activating its data harvesting capabilities. It bombards users with nag-screens across every webpage they visit, claiming that the ad-blocking features of the extension will not function as intended unless the user agrees to share their data. To evade automated security reviews and researchers, the extension deliberately waits 24 hours after installation before silently connecting to a remote server to download the executable malicious code.


Additionally, the extension ensures activation by manipulating its user interface. The settings menu utilizes inverted toggles; for example, if a user flips the “Opt Out” switch to the “On” position to protect their privacy, they are actually opting in to data collection. Agreeing to share your data or ‘opting-in’ allows the vendor to claim to platform reviewers that the data collection is consensual, and they can therefore avoid being removed from the extension stores.

Once the user is tricked into providing consent, the extension silently downloads the malicious payloads from the remote servers in the background. This grants the spyware the access it needs to harvest and observe the following data:
- Browsing and navigation history: Detailed logs of the websites you visit.
- AI chatbot conversations: Your private conversations and interactions with AI platforms including ChatGPT, Claude, and Gemini.
- Social media and advertising data: Data regarding your social media interactions and ad engagements.
- Browser fingerprint: Unique system and configuration details used to identify your device online.
- Cloudflare clearance: Security tokens used to bypass bot detection on websites.
- Cross-device identifiers: Identifiers that allow tracking across multiple devices.
Recommendations
PSA Intelligence notes that browser extensions represent one of the most critical yet overlooked attack vectors, as these extensions get installed with almost no friction, and their permissions and privacy policies are often not thoroughly read or understood. Beyond deceptive apps designed maliciously from the start, initially legitimate extensions can suddenly go rogue for various reasons:
- Initial developer compromise: A developer might intentionally compromise their own product, either by monetizing their user base with data-harvesting tracking code or by selling the extension to a malicious third party.
- A compromised developer: The developer might have been a victim of a cyber incident via phishing or stolen credentials.
- Supply chain attacks: Threat actors can compromise an underlying third-party code library or dependencies the extension relies on, affecting downstream users or organizations.
Cybersecurity Vulnerabilties
Apple Releases Patch Update for Zero-Day CoreGraphics Flaw: CVE-2026-86950
On September 29, Apple released a patch update for iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1 to address a zero-day vulnerability, CVE-2026-86950. It has a Common Vulnerability Scoring System (CVSS) score of 8.8. This is Apple’s seventh zero-day fix for 2026.
Apple disclosed that the flaw could allow a maliciously crafted file to trigger out-of-bounds arbitrary code execution in the CoreGraphics Framework, and credited Meta’s Product Security team for discovering the vulnerability. Threat intelligence researchers disclosed that the flaw was likely exploited in an "extremely sophisticated" attack targeting high-profile individuals, such as high-value executives and high-ranking politicians. Mercenary spyware-class operations typically target this narrow set of individuals, representing ongoing cybersecurity threats instigated and organized by state- and non-state-sponsored advanced persistent threat (APT) actors.
The vulnerability affected devices including the iPhone 11 and later, iPad Pro 12.9-inch (3rd generation) and later, several other iPad models, and Mac devices running macOS Sequoia 15.8.1 and Tahoe 26.7.1. PSA Intelligence notes that no further information regarding technical details, identified threat actors, or compromised entities was disclosed by Apple.
The Importance of Keeping Your Devices Updated
PSA Intelligence emphasizes the importance of keeping software and devices up to date with the latest security patches, as these close the specific software vulnerabilities required to trigger exploits. While updating to the latest iOS version is often recommended, Apple simultaneously releases alternative security updates. This ensures that users with aging hardware or compatibility issues with in-house enterprise apps can still stay updated with the latest security patches.
Cisco Catalyst SD-WAN Manager Vulnerability Enables Authentication Bypass: Added to CISA’s KEV List (CVSS 9.8)
Networking hardware company Cisco warned of a vulnerability that enables threat actors to remotely access vulnerable systems with admin privileges. Identified as Common Vulnerabilities and Exposures (CVE)-2026-76504, the zero-day vulnerability allows threat actors to exploit improper handling of URI encoding in an HTTP request to achieve authentication bypass.
Cisco Catalyst SD-WAN Manager, formerly known as SD-WAN vManage, is an enterprise network management software used in virtual machines, data centers, and cloud hosting. It allows admins to monitor and manage up to 6,000 SD-WAN devices from a single dashboard. However, a flaw in the API session-based authentication management allows an unauthenticated, remote attacker to send a specially crafted HTTP request to the API. This bypasses an authentication rule intended to restrict access to a specific API endpoint, subsequently granting access to the system.
The vulnerability carries a Common Vulnerability Scoring System (CVSS) score of 9.8.
The United States (US) Cybersecurity and Infrastructure Security Agency (CISA) has confirmed this flaw is actively exploited and has added it to its Known Exploited Vulnerabilities (KEV) list. CISA has ordered U.S. federal agencies to secure their systems against these attacks by Saturday, October 3.
To address this, Cisco has strongly advised customers to upgrade to a fixed software release to remediate the vulnerability. For full details, refer to the National Vulnerability Database (NVD) entry for CVE-2026-76504.
