SonicWall SMA 1000 zero-days (CVSS 10.0 SSRF and RCE) and JFrog Artifactory auth bypass are actively exploited; AI coding agents face new GitSpawn code execution class. Two SonicWall SMA 1000 CVEs were exploited as zero-days: a pre-auth SSRF rated CVSS 10.0 and a post-auth RCE. JFrog self-hosted Artifactory deployments face active exploitation of a CVSS 9.8 authentication bypass yielding admin tokens. Separately, GitSpawn exposes major AI coding agents to arbitrary code execution via malicious Git configs.
JSCeal
3 posts
7th September – Threat Intelligence Report - Check Point Research Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode - Check Point Research JSCeal is a Node.js-based stealer delivered as compiled V8 bytecode that targets browser credentials, cryptocurrency wallets, and Telegram sessions. The malware implements a local HTTPS interception proxy with attacker-controlled certificate installation, modifies responses for cryptocurrency platforms, and uses Puppeteer to automate Google OAuth token theft. Check Point Research developed a static deobfuscation pipeline extending the View8 decompiler to recover readable pseudocode from the obfuscated V8 bytecode, enabling analysis of the malware's full capability set.
Day 2 at Black Hat: Check Point Research Takes the Stage Check Point Research presented three talks at Black Hat covering: (1) a Windows Defender kernel driver (BTR) with a hardcoded encryption key across all signed builds spanning Windows 7–11 25H2, enabling arbitrary Ring 0 operations with no CVE or patch; (2) twelve CVEs across four major AI agent frameworks where poisoned content triggers exploitation through framework serialization and caching internals without direct tool invocation; and (3) a deobfuscation pipeline for JSCeal, a V8 bytecode-compiled cryptocurrency stealer whose payloads include credential theft, keylogging, and HTTPS interception.