Home › Weekly Digests › This Week
LiveThreat Threat Intelligence

Weekly Threat Intelligence Digest — Sep 17 to Sep 24, 2026

Weekly threat intelligence digest from 267 items (21 critical, 185 high).

September 24, 2026 267 articles analyzed
LIVETHREAT WEEKLY THREAT DIGEST September 17 – September 24, 2026 This week’s data underscores a growing reality: breaches are less about a single vulnerability and more about who holds the keys. From ransomware groups hijacking MSP admin consoles to supply‑chain attacks on Brevo and Gyazo, the common denominator is privileged access flowing through trusted third parties. At the same time, a wave of critical authentication‑bypass flaws—Cisco ISE, F5 BIG‑IP APM, Check Point—showed how a single mis‑configured service can unlock entire enterprises. Finally, AI‑driven agents and mis‑configurations (Google Gemini, Claude, autonomous AI agents) are being weaponized, stretching control‑assurance boundaries beyond traditional perimeter defenses. 👉 Access, not just vulnerability, is the primary risk driver. 🚨 EXECUTIVE RISK SNAPSHOT * Supply‑chain paths → MSP admin panels, CI/CD registries, SaaS API keys were the first foothold in multiple incidents. * Privilege amplifies impact → A compromised cloud admin account enabled exfiltration of >80 TB of data across 100 k customer sites. * Blind‑spot assets → OT/IoT networks and edge devices remain largely invisible to most control inventories, creating audit gaps. 🔍 WHAT CHANGED THIS WEEK * Attackers increasingly target “trusted” credentials (e.g., hard‑coded Cloudflare API keys, stolen Terraform provider tokens). * Critical auth‑bypass CVEs (CVE‑2026‑76460, CVE‑2026‑94127) moved from disclosure to active exploitation within days. * AI agents are being used to automate privilege escalation and data manipulation, exposing gaps in AI governance controls. * OT incidents (oil‑tanker propulsion, water‑utility SCADA) highlight the convergence of cyber and physical risk. 🎯 WHERE YOU ARE MOST LIKELY EXPOSED * SaaS platforms that expose admin APIs without mandatory MFA (Snowflake, F5 BIG‑IP, Cisco ISE). * CI/CD ecosystems that allow third‑party Terraform or npm packages to execute code (Terraform Registry, npm). * Cloud hosting accounts with shared credentials or hard‑coded secrets (AWS me‑south‑1, Azure, GCP). * OT and maritime control systems that lack integrated logging and patch management. * AI‑enabled services (Gemini, Claude, OpenAI) that have not been sandboxed or audited for data‑flow controls. ⚡ WHAT COMPLIANCE & SECURITY LEADERS SHOULD DO THIS WEEK 1. **Map privileged access flows** – Identify all admin accounts, API keys, and service‑to‑service credentials. • Verify MFA enforcement for every privileged login. 👉 Ask: “Can we produce MFA logs for every admin session on demand?” 2. **Validate third‑party code pipelines** – Audit all Terraform providers, npm packages, and CI/CD scripts for unauthorized changes. • Enforce signed artifacts and provenance checks. #TrustOperations #NISTCSF #ControlAssurance #Cybersecurity #ThreatIntel #ContinuousMonitoring #LiveThreat #VerisqAI

Articles Referenced in This Digest 267 items

Advisory (41)

CriticalMicrosoft Plugs Nearly 1,000 Security Holes
HighMultiple Vulnerabilities in Adobe Products Could Allow for Arbitrary Code Execution
HighUK regulator to investigate Pornhub parent company for alleged age verification failings
HighConsiderations for Critical Infrastructure Operators Working With Third-Party ICS Integrators
HighMicrosoft: September Windows updates break Always On VPN connections
HighSome cheap smart glasses are a security disaster
HighGoogle Fined €403 Million Over Location Data Practices
HighGoogle hit with €403 million GDPR fine over location tracking
HighGoogle Fined €403 Million Over GDPR Violations Tied to Location Data
HighEU data regulator fines Google more than $460 million for location data violations
HighMicrosoft reminds admins to migrate Entra ID users to passkeys
HighMicrosoft: September updates break File History backup feature
HighOpenAI admits its models lie to cover their own mistakes
HighEuropean Commission set to push social media restrictions, safety requirements into law
HighMultiple Vulnerabilities in Oracle Products Could Allow for Arbitrary Code Execution
HighWindows 11 24H2 Home and Pro reach end of support in October
HighChosen Brick, Iran’s Surveillance Malware
HighMicrosoft shares workaround for Windows domain login issues
HighLG to Ban Residential Proxies from Smart TV Apps
MediumNetwork Solutions Dark Web Monitoring alerts small businesses to domain-linked data exposure
Medium FBI's CJIS v6.1: What Security Teams Need to Know.
MediumMicrosoft fixes broken Excel copy and paste for all Office users
MediumMicrosoft to retire Microsoft 365 Companion apps in December
MediumBuilding Crypto Agility Across the Enterprise
MediumMicrosoft fixes bug behind ‘Defender Antivirus is turned off’ alerts
MediumMicrosoft Teams will let admins block custom file extensions
MediumMicrosoft fixes broken copy and paste for Excel 2016 users
MediumAdversary simulation: what you need to know
InformationalMobile App Security in HealthTech: Safeguarding Patient Data Against Cybersecurity Threats
InformationalCISA Lays Out Future of CVE Vulnerability Program
InformationalReducing shadow IT visibility gaps with Wazuh
InformationalSES Complete Is a Certified Leader in the AV-Comparatives EPR Test
InformationalHow to Comply with MiCA Regulations for Crypto Asset Service Providers in the European Market?
InformationalGoogle Wants Android Apps to Look Beyond the Security Patch Date
InformationalHTTP QUERY Method: The Grey Zone Between GET And POST., (Fri, Sep 18th)
InformationalCISA Ditches Weekly Vulnerability Roundups for Risk-Based Focus
InformationalImproving email security outcomes with real-world Microsoft Defender insights
InformationalFrom guidance to action: Security fundamentals that materially reduce risk 
InformationalCan You Prove a New CVE Is Exploitable Before Attackers Do? Learn How in This Webinar
InformationalCyber Adversary Simulation (CyAS): scheme documents now available
InformationalGoogle’s new agent security system detects tool misuse, loops and rogue behavior

Breach (43)

HighOpen-Source AI Agents Breach 27 Companies, Steal 600,000 Credit Card Records
HighA Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You
HighMalicious AI agents steal 600K credit cards, infect 100+ sites with skimmers
HighLatvia arrests suspected hacker for electronics repair company breach
HighFBI investigating alleged ShinyHunters breach of its jobs site
HighShinyHunters claims FBI breach after alleged PeopleSoft zero-day attack
HighNightmare Eclipse Reveals Name, Story Behind MS Zero-Days
HighLinkedIn wins court order blocking mass scraping of user data
HighCyberattack hits University of Munich, potentially exposing student financial data
HighBelgian table tennis, gymnastics federations hit by cyberattacks
HighGoogle fined €403 million over location data privacy violations
HighBigCommerce alerts merchants of data breach linked to Ribon apps
HighAmbry Genetics Pays $700K HIPAA Fine in Phishing Breach
HighA week in security (September 14 – September 20)
HighShinyHunters hacks rival extortion gang and takes over its dark web site
HighForeign Hackers Target Two Colorado Water Utilities
HighBurger King Russia - 3,155,792 breached accounts
HighGroup Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO
HighHackers exploit Gyazo server flaw to steal 23.6 million user records
HighJade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors
HighSecurity Affairs newsletter Round 595 by Pierluigi Paganini – INTERNATIONAL EDITION
HighSECURITY AFFAIRS MALWARE NEWSLETTER ROUND 115
HighHackers Crack Flock Camera, Expose 1.6M Images in 21 Days
HighAI Helps Hackers Hijack OpenAI Staff Accounts Through a Forum
HighGoogle Gemini also Broke Out of Its Test Environment
HighShinyHunters hacks Clop leak site, threatens to extort ransomware gang
HighCrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories
HighGoogle Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up
HighClaude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws
HighBrevo Supply-Chain Attack Infected Over 100,000 Websites
HighGyazo server flaw exploited to steal 23.6 million user records
HighDon’t Call Us, We’ll Call Your APIs | TraderTraitor Backdoors Resurface on Victim With No Crypto Ties
HighAI Agent Breaches Spanish Organization, Modifies Personal Data
HighCyberattacks on Oil Tankers Put Maritime Critical Infrastructure at Risk
HighRevolut phishing texts appear days after data breach
HighUS Coast Guard and FBI board oil tanker to investigate cyber attack
HighIranian strikes on AWS facilities left customer data beyond recovery in Bahrain, UAE
HighBrevo supply-chain attack injected ClickFix scripts on customer sites
HighGyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Records
HighHackers claim breach of Russian election systems days before parliamentary vote
HighCanadian Man Pleads Guilty in Snowflake Extortions
MediumShinyHunters Hacks and Defaces Clop Ransomware Leak Site
InformationalBreach Roundup: China Calls for Stronger AI Oversight

Ransomware (2)

CriticalBerlin Ransomware Leak Exposes State Secrets
HighRyuk ransomware operator gets 2-year sentence after extorting victims for $1.2 million

ThreatIntel (133)

CriticalF5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers
HighMicrosoft Disrupts AI-Powered EvilTokens Service Linked to 12,000 Hacked Inboxes
HighSmashing Security podcast #486: Vibe-coded shops, and hackable Flock cameras
HighEDR Evasion Stack Helps Process Injection Slip Past Defenses
HighThe Lure Isn't The Malware. It's Your Logo.
HighFake Claude Max giveaway tricks users into handing over their Google account credentials
High80,000 relay servers help users in China slip past U.S. AI region bans
HighAttackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry
HighPlaceholder domain used in dev docs now serves ClickFix attacks
HighUAE, Saudi Arabia Face Onslaught of Increasingly Complex Cyberattacks
HighZDI-26-719: Cisco ThousandEyes Virtual Appliance DHCP Client Command Injection Remote Code Execution Vulnerability
HighNetBSD 10.2 security fixes close a remote kernel bug in ipfilter
HighChinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware
HighRyuk ransomware member sentenced to 24 months in prison
HighFrom Payment Plan to Ransomware - Inside a Global Group Attack
HighThe Closed Quorum: Inside the first reported autonomous AI C2 implant
HighAI Agents Are Rewriting the Rules of Lateral Movement
HighMicrosoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises
HighTwo arrested in UK after Microsoft takedown of ‘Eviltokens’ AI-chatbot for cybercriminals
HighNew TASK#STOMP Windows Backdoor Enables Continuous Document Theft
HighA cheap fake base station can still track 5G subscribers
HighSideCopy Broadens India Targeting to Academia With ReverseRAT Spear-Phishing
HighClickFix Attacks Spread ChainScript RAT via Fake Spotify and Teams Installers
HighChina-Linked FamousSparrow Deploys SparroWocky Backdoor in Latin America
HighRogue Behavior: OpenAI Reveals More Model Misalignment Incidents
HighCybercriminals Are Hiding New Malware in Torrents for Popular Films
HighShinyHunters Hacked Clop. Now What About Clop's Victims?
HighHow AI Agents Can Trigger Runaway Costs for Enterprises
HighReverse-Engineering Flock Cameras
HighThe AI models that cheat the most, according to new CAIS benchmark
HighNorth Korea’s job interview scam runs both ways
HighThe TASK#STOMP Windows backdoor takes Wi-Fi passwords, screenshots, and business files
HighTASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data
High⚡ Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacks
HighContagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in Crypto
HighFake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR
HighShinyHunters cybercrime gang takes over Cl0p ransomware site, demands extortion payment
HighCyber Extortion War: ShinyHunters Holds Rival Clop to Ransom
HighGoogle Gemini Agents Access Real Companies in AI Safety Test
HighGemini’s breach of real companies exposes an AI guardrail problem
HighThe fake sites using a cheap toolkit to sell $2,000 AI subscriptions
HighUK Police Data Faces Long-Standing Microsoft Cloud Security Concerns
HighA BYD Shark 6 Hack Shows the Risks of Connected Cars
HighChainScript: the RAT that hides its command server inside a blockchain contract
HighTerminalFix: PNG Steganography, (Mon, Sep 21st)
HighExecution Runtime Security in the Era of Agentic AI
HighFrom Exposure to Lockdown: How AWS Neutralizes Compromised IAM Credentials through Managed Policies
HighAI compliance issues hit 2 in 5 large companies, and legacy workflows are a big factor
HighIntent injection attacks are a new worry for AI-native 6G networks
HighScammers impersonate cops, use arrest threats to extort victims
HighClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure
HighRussia reports thousands of cyberattacks on election infrastructure during vote
HighMalicious npm packages evade install-script defenses at runtime
HighAI Hallucinations Nearly Triggered a US-China Military Confrontation
HighUAE Cyber Chief Says Country Faced 640,000 Cyberattacks in One Day
HighHackers Are Using Passkey Updates as a New Microsoft Phishing Hook
HighNorth Korean WaterPlum hackers infected 30,000 devices worldwide
HighNorth Korean hackers infect thousands of devices across 100 countries as part of ‘WaterPlum’ campaign
HighMFA Won't Save You From OAuth Consent Abuse
HighFake calendar invites can infect your system, and they’re surging – how to protect yourself
HighFake LastPass Authenticator GitHub repos push new Rapuncel infostealer
HighCyber Defense Alone Can't Keep Critical Services Running
HighChina Hackers Hit Latin American Governments With Backdoor
HighFake parcel delivery messages steal your card and bank details
HighDid an AI really try to break free from human control?
HighNew Android malware uses AI to steal bank logins and PINs
HighRatHat Turns Android Accessibility Into an Attack Weapon
HighRatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall
HighClaimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer
HighHardcoded MCP credentials found in public GitHub files
HighInside the Modern SOC: Defending the Cross-Environment Pivot
HighIran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords
HighThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Stories
HighLausivLoader analysis, or how to pass data between malware stages, (Thu, Sep 17th)
HighChina's FamousSparrow APT Spies on US Politics in Latin America
HighA fake ChatGPT billing email is after your OpenAI password
HighWhat Recent AI-Powered Attacks Mean for Your Identity Security
HighOpenAI details more cases of AI agents taking unauthorized actions
HighNew RatHat Android malware uses AI to automate device control
HighOpenAI Finds Models Writing Their Own Rogue Instructions
HighChatbot Conundrum: Phishing Attempts of OpenAI’s ChatGPT
HighSilkParasite Infrastructure Links SpiceRAT to Central Asian Targets
HighU.S. Seizes NightmareStresser Domains Linked to Hundreds of Thousands of DDoS Attacks
HighChina-Aligned FamousSparrow Deploys SparroWocky Backdoor Across Latin America
HighCISO's Expert Guide to Agentic Pentesting for Websites
HighIsraeli contractor BlackCore trained Angolan officials in online influence operations
HighChina’s FamousSparrow hackers target Latin America with new backdoor
HighNightmareStresser Goes Offline in Global DDoS-for-Hire Crackdown
HighFake AI trading agent steals crypto wallet passwords
HighFBI takes down one of the longest-running DDoS-for-hire services
HighAnthropic wants Claude to analyze your bank account and financial data
HighChinese hackers use SparroWocky malware in govt espionage attacks
HighUS takes down NightmareStresser DDoS-for-hire platform
HighT-Mobile rewards points expiry texts are a phishing scam
High12 celebrity deepfake websites seized by Manhattan DA
HighRead This Before You Buy That TV Streaming Stick
HighTwo Alleged ‘TeamPCP’ Hackers Arrested in Australia
HighData Broker Radaris Loses Domains in Privacy Fight
MediumCofense measures employee readiness against real-world phishing threats
MediumWeekly Update 522: Live From Oslo with Scott Helme
MediumWebinar tomorrow: Inside real-world Google Workspace breaches
MediumGPT-6 Astra Breaks an Old Enigma Message
MediumThe next intellectual property thief may sound like your CEO
MediumThe Target Is No Longer the Model. It’s the Agent.
MediumKnow what was tested before your SAP ECC migration goes live
MediumSiemba brings continuous IDOR testing to production APIs
MediumViral AI actress' hotline face-scans every caller, watches their mood
MediumIdentity Visibility in 2026: The Foundation of Identity Security
MediumCalling viral AI actress Tilly Norwood? Agree to a face scan first
MediumBusinesses finally seeing AI ROI, but 62% can’t handle the storage demands
MediumWebinar: Which Google Workspace security controls actually matter?
MediumSecure enterprise sharing with access reviews for Microsoft 365
MediumMost WordPress pros still lack a breach recovery plan
MediumBots with good manners are better at fooling people on social media
MediumDownload: The IT leader’s guide to AI code sprawl
MediumStates Expand Cyber Support Beyond Their Own Networks
InformationalOpenAI Expands Outside Safety Reviews Into Model Training
InformationalEmail Makes Up Nearly 1 in 3 MSSP Analyses: How Tier 1 Can Triage Phishing Faster
InformationalNo evidence of successful foreign meddling in 2024 election, spy agencies found
InformationalPhone Hacking Software Firm Hid Russian Ownership, Say Feds
LowDeception by Design: CISA's Guide to Tricking Cybercriminals
InformationalGPT-6 Sol and Luna arrive with 50% lower API prices
InformationalFastly gives enterprises real-time control over AI models and agents
InformationalISC Stormcast For Monday, September 21st, 2026 https://isc.sans.edu/podcastdetail/10102, (Mon, Sep 21st)
InformationalVectra AI Launches Ascent to Help Address New Era of AI-Driven Attacks
InformationalDARPA Seeks AI Tools to Transform Battlefield Medical Care
InformationalISC Stormcast For Friday, September 18th, 2026 https://isc.sans.edu/podcastdetail/10100, (Fri, Sep 18th)
InformationalArcjet brings security controls and audit trails to AI agents
InformationalThe New Rules of Machine Speed Defense
InformationalDruva expands identity resilience with ransomware detection
InformationalISC Stormcast For Thursday, September 17th, 2026 https://isc.sans.edu/podcastdetail/10098, (Thu, Sep 17th)
InformationalTuskira Vector brings autonomous red teaming to attack surface validation
InformationalWho’s Tracking You? Use This New Service to Find Out

Vulnerability (48)

CriticalNew cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control
CriticalCritical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input
CriticalF5 patches BIG-IP APM zero-day flaw exploited in RCE attacks
CriticalCheck Point warns of Management Server zero-day exploited in attacks
CriticallwIP TCP/IP Stack MQTT Client Application
CriticalWeek in review: Cisco patches exploited email gateway 0-day, Revolut breach
CriticalCISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild
CriticalCritical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild
CriticalPublic Exploits Released for Four Linux Kernel Flaws That Enable Local Root
CriticalCisco Zero-Day Highlights API Endpoint Authentication Issues
CriticalCheck Point Fixes Critical CVE-2026-91843 Allowing Root Code Execution
CriticalZero-click RCE vulnerability hit four major AI coding agents, two remain unpatched
CriticalNew Check Point flaw lets hackers execute code with root privileges
CriticalCritical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files
CriticalCritical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root
CriticalCisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks
CriticalU.S. CISA adds Acronis Backup, Cisco ISE, and Google Pixel flaws to its Known Exploited Vulnerabilities catalog
CriticalCisco warns of max severity ISE zero-day exploited in attacks
HighGitLab Email Addresses Can Be Weaponized for Supply Chain Attacks
HighMikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key
HighMedical Imaging Archive Flaws Put Patient Scans at Risk
HighPublic PoC Exposes Critical Veeam Agent Privilege Escalation
HighWordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session
HighNew Windows Defender zero-day blocks Microsoft antivirus updates
HighWordPress Click2Shell flaw lets hackers execute PHP on the server
HighCISA alerts of active exploitation of three Linux kernel flaws
HighCISA Adds One Known Exploited Vulnerability to Catalog
HighU.S. CISA adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog
HighResearchers escape OpenAI Codex sandbox to run commands on host
HighBragJack attacks hijack AI browser agents through malicious extensions
HighSolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE
HighZDI-26-715: Linux Mint Xreader PDF File Parsing Type Confusion Remote Code Execution Vulnerability
HighZDI-26-716: Cisco Identity Services Engine createDBLink Command Injection Remote Code Execution Vulnerability
HighZDI-26-717: Cisco Identity Services Engine AlarmMessageDiskQueue Deserialization of Untrusted Data Remote Code Execution Vulnerability
HighCISA Adds One Known Exploited Vulnerability to Catalog
HighCISA Adds Two Known Exploited Vulnerabilities to Catalog
HighZDI-26-714: Samsung rlottie Stack-based Buffer Overflow Remote Code Execution Vulnerability
HighABB Ability Edgenius
HighSchneider Electric Modicon M340 Controller and Communication Modules
HighSchneider Electric NetBotz 5 750/755
HighBransys ELD
HighMitsubishi Electric GX Works3 and Motion Control Settings
HighUnauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460)
HighZDI-CAN-33991: Foxit
HighMicrosoft Patches a Record 570 Security Flaws
HighMicrosoft Plugs Nearly 400 Security Holes
MediumZDI-26-718: Cisco Identity Services Engine MnTRESTLivelogService XML External Entity Processing Information Disclosure Vulnerability
MediumSchneider Electric PowerChute Serial Shutdown

Daily breach, advisory, and vulnerability briefs publish every weekday.

View Live Breach Feed ← All Weekly Digests