Home › Weekly Digests › This Week
LiveThreat Threat Intelligence

Weekly Threat Intelligence Digest — Sep 21 to Sep 28, 2026

Weekly threat intelligence digest from 241 items (8 critical, 84 high).

September 28, 2026 241 articles analyzed
LIVETHREAT WEEKLY THREAT DIGEST September 21 – September 28, 2026 This week the data showed that the most damaging breaches were not caused by a single vulnerability but by compromised privileged accounts inside trusted third‑party ecosystems. From North Korean actors hijacking a crypto‑exchange admin console to supply‑chain backdoors planted in an Indian IT services firm, the common thread is privileged access flowing through vendors. At the same time, a surge of zero‑day exploits in F5 BIG‑IP, Citrix NetScaler and Oracle PeopleSoft amplified the impact of those access breaches, driving massive data loss and regulatory fines. 👉 Access – especially when it lives in a vendor or cloud admin role – is the primary risk vector this week. 🚨 EXECUTIVE RISK SNAPSHOT * Supply‑chain entry points dominate → MSPs, SaaS admin consoles, CI/CD pipelines and OT integrators were the first footholds in 9 of the 12 breach incidents. * Privilege determines impact → A single compromised cloud admin account enabled theft of $351 M and exposure of 23.6 M user records; AD GPO hijacks disrupted entire domains. * Blind spots persist → OT/IoT devices, fourth‑party code libraries and unmanaged cloud containers remain outside most inventories, leaving auditors without evidence. 🔍 WHAT CHANGED THIS WEEK * Attackers are chaining zero‑day exploits with privileged credentials to amplify reach across multiple vendors. * AI‑driven agents are being used to probe and exfiltrate data from government portals and corporate APIs, highlighting a new class of autonomous supply‑chain risk. * Ransomware groups are targeting Active Directory group‑policy objects, turning a control‑framework artifact into a delivery mechanism. * Cloud misconfigurations and third‑party dependency flaws (e.g., API keys, CI/CD secrets) are surfacing as high‑impact vectors in both SaaS and OT environments. 🎯 WHERE YOU ARE MOST LIKELY EXPOSED * Cloud hosting admin consoles – AWS, Azure, F5 BIG‑IP, Citrix NetScaler – especially if MFA or session monitoring is missing. * Third‑party API providers and ERP platforms – PeopleSoft, WSO2, Oracle, API gateways – where credential leakage or WAF bypass is reported. * Managed service providers and MSPs – their privileged service accounts often lack granular audit trails. * CI/CD pipelines – GitHub Actions, Terraform providers, and container registries that store secrets in plaintext. * OT and industrial control systems – water utilities and manufacturing PLCs that still rely on default credentials and lack network segmentation. ⚡ WHAT COMPLIANCE & SECURITY LEADERS SHOULD DO THIS WEEK 1. Map privileged‑access incidents to your control framework • Identify which NIST CSF, ISO 27001, or SOC 2 controls cover admin console management, vendor‑access reviews and AD GPO changes. #TrustOperations #NISTCSF #ControlAssurance #Cybersecurity #ThreatIntel #ContinuousMonitoring #LiveThreat #VerisqAI

Articles Referenced in This Digest 241 items

Advisory (46)

HighCISA Adds Two Known Exploited Vulnerabilities to Catalog
HighKiteworks Urges Customers to Shut Down Systems for 9 Hours Over Possible Cyber Attack
HighU.S. CISA adds Microsoft SharePoint and Mikrotik RouterOS flaws to its Known Exploited Vulnerabilities catalog
HighKiteworks urges 6-hour server shutdown over potential zero-day attacks
HighKiteworks urges customers to stop using platform after warning from federal intelligence agencies
HighCISA And FBI Warn OT Operators About Third-Party Hacking
HighYour LG TV is constantly collecting your data – here’s how to stop it
HighUnpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions
HighCloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data
HighFedRAMP VDR & VER: Daily Scans Are Only the Beginning
HighLawmakers introduce bill for voluntary telecom cyber rules after Salt Typhoon hacks
HighCISA Adds Two Known Exploited Vulnerabilities to Catalog
HighCISA Adds Two Known Exploited Vulnerabilities to Catalog
HighGoogle’s location data privacy failures draw a €403 million fine
HighMultiple Vulnerabilities in Adobe Products Could Allow for Arbitrary Code Execution
HighUK regulator to investigate Pornhub parent company for alleged age verification failings
HighConsiderations for Critical Infrastructure Operators Working With Third-Party ICS Integrators
HighMicrosoft: September Windows updates break Always On VPN connections
HighSome cheap smart glasses are a security disaster
HighGoogle Fined €403 Million Over Location Data Practices
HighGoogle hit with €403 million GDPR fine over location tracking
HighGoogle Fined €403 Million Over GDPR Violations Tied to Location Data
HighEU data regulator fines Google more than $460 million for location data violations
HighMicrosoft reminds admins to migrate Entra ID users to passkeys
HighMicrosoft: September updates break File History backup feature
MediumHow to fix your Windows File History if the September update broke it
MediumIs your Apple Watch 12 or Ultra 4 randomly restarting? Here’s the fix
MediumMicrosoft: Recent Windows updates cause desktop loading issues
MediumMicrosoft plans to deprecate Windows Deployment Services
MediumNetwork Solutions Dark Web Monitoring alerts small businesses to domain-linked data exposure
Medium FBI's CJIS v6.1: What Security Teams Need to Know.
MediumMicrosoft fixes broken Excel copy and paste for all Office users
MediumMicrosoft to retire Microsoft 365 Companion apps in December
MediumBuilding Crypto Agility Across the Enterprise
InformationalCISA Unveils US Midterm Election Security Plan
InformationalDocker introduces OCI-based Kits to package agents and their guardrails
InformationalWindows 11 KB5124010 update released with 46 changes and fixes
Informational​​​​​​​​What’s new in Microsoft Security: September 2026​​
InformationalNew Browser Guard features add protection before and after you click
InformationalAgents can now set up your website’s security with Turnstile Spin
InformationalMobile App Security in HealthTech: Safeguarding Patient Data Against Cybersecurity Threats
InformationalCISA Lays Out Future of CVE Vulnerability Program
InformationalReducing shadow IT visibility gaps with Wazuh
InformationalSES Complete Is a Certified Leader in the AV-Comparatives EPR Test
InformationalHow to Comply with MiCA Regulations for Crypto Asset Service Providers in the European Market?
InformationalGoogle Wants Android Apps to Look Beyond the Security Patch Date

Breach (32)

CriticalBitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise
HighSecurity Affairs newsletter Round 597 by Pierluigi Paganini – INTERNATIONAL EDITION
HighWeek in review: Gyazo breach exposes 23.6M user data, TASK#STOMP steals documents
HighU.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions
HighLabcorp to overhaul data security practices, pay $2.3 million fine for cybersecurity failings
HighTeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords
HighOpenAI Agent Bypassed Australian Medicare Portal Controls to Access Non-Public Files
HighHackers steal $351.6 million in Bitget crypto exchange hack
HighCrypto CEO accuses North Korea of stealing $387 million from Bitget platform
HighOpenAI agent breached Australian government site, took months to report it
HighOpen-Source AI Agents Breach 27 Companies, Steal 600,000 Credit Card Records
HighA Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You
HighMalicious AI agents steal 600K credit cards, infect 100+ sites with skimmers
HighLatvia arrests suspected hacker for electronics repair company breach
HighFBI investigating alleged ShinyHunters breach of its jobs site
HighShinyHunters claims FBI breach after alleged PeopleSoft zero-day attack
HighNightmare Eclipse Reveals Name, Story Behind MS Zero-Days
HighLinkedIn wins court order blocking mass scraping of user data
HighCyberattack hits University of Munich, potentially exposing student financial data
HighBelgian table tennis, gymnastics federations hit by cyberattacks
HighGoogle fined €403 million over location data privacy violations
HighBigCommerce alerts merchants of data breach linked to Ribon apps
HighAmbry Genetics Pays $700K HIPAA Fine in Phishing Breach
HighA week in security (September 14 – September 20)
HighShinyHunters hacks rival extortion gang and takes over its dark web site
HighForeign Hackers Target Two Colorado Water Utilities
HighBurger King Russia - 3,155,792 breached accounts
HighGroup Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO
HighHackers exploit Gyazo server flaw to steal 23.6 million user records
HighJade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors
MediumOpenAI's AI agents accidentally uploaded user-provided images to third-party sites
MediumShinyHunters Hacks and Defaces Clop Ransomware Leak Site

Ransomware (2)

HighUkrainian ransomware developer jailed for nearly 13 years
HighRyuk ransomware operator gets 2-year sentence after extorting victims for $1.2 million

ThreatIntel (116)

CriticalF5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers
HighSECURITY AFFAIRS MALWARE NEWSLETTER ROUND 116
HighRydox Admin Faces 20 Years After Selling Stolen Data and Fraud Tools
HighShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks
HighExploit.in Database Reveals the Roots of Today’s Ransomware Ecosystem
HighZero Trust for AI Agents Starts With Fixing Zero Visibility
HighLunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials
HighGitHub Actions re-enabled with Mini Shai-Hulud payload still active
HighMicrosoft pauses KB5002907 update after Office license deactivations
High5G-Shark Lures Phones to Rogue 5G Cells Without Network Jamming
HighAI Sandbox Escapes: Why Forensic Readiness Matters More Than Containment
HighUsing Threat Intelligence to Stop Ransomware Attacks
HighUS Appeals Court Backs Pentagon Blacklisting of Anthropic
HighTrust and the enticing consultancy offer
HighSectopRAT Returns, Hiding Inside a Legitimate Application
High'Salesbleed' Exploits Salesforce Agents to Enable Slack Phishing
HighAI agent kill switch urged by Okta-led alliance – how businesses could make it work
HighMacSync under the microscope: new delivery methods and a new payload
HighYour incident count is missing a few incidents
HighStop watching what AI agents say and start watching what they do
HighFake payroll desktop apps hand attackers a route to company paychecks
HighMacSync info-stealing malware hides malicious commands in an iCloud calendar
HighThreat detection dashboards are masking security coverage gaps
High17,000 URLs Reveal How ClickFix Turns Trusted Websites Into Malware Traps: Report by CTM360
HighSecrets Sprawl Is an Identity Problem That AI Just Made Impossible to Ignore
HighCorp MDM Spyware Targets Logistics Firms, Steals New SMS and Redirects Calls
HighHacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer
HighThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories
HighThe SOC Doesn't Need to Start Over with Every Alert
HighPamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence
HighCompromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware
HighMacSync malware uses public iCloud calendars to deliver new payloads
HighDigital forensics firm with US federal contracts covered up ties to Russia, DOJ alleges
HighCyberattack hits Welsh police force, may have affected staff data
HighBeyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments
HighStorm-3168: Agentic-driven cloud attacks using compromised service principals
HighFake Claude Max giveaway hides a Google account phishing trap
HighHow device code phishing gives scammers access to your account
HighThat shipping rebate offer may come with a monthly charge
HighCriminals turn placeholder domain into ClickFix trap
HighKothamine malware uses Tailscale’s tailcat to evade network detection 
HighMicrosoft Disrupts AI-Powered EvilTokens Service Linked to 12,000 Hacked Inboxes
HighSmashing Security podcast #486: Vibe-coded shops, and hackable Flock cameras
HighEDR Evasion Stack Helps Process Injection Slip Past Defenses
HighThe Lure Isn't The Malware. It's Your Logo.
HighFake Claude Max giveaway tricks users into handing over their Google account credentials
High80,000 relay servers help users in China slip past U.S. AI region bans
HighAttackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry
HighPlaceholder domain used in dev docs now serves ClickFix attacks
HighUAE, Saudi Arabia Face Onslaught of Increasingly Complex Cyberattacks
HighZDI-26-719: Cisco ThousandEyes Virtual Appliance DHCP Client Command Injection Remote Code Execution Vulnerability
HighNetBSD 10.2 security fixes close a remote kernel bug in ipfilter
HighChinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware
HighRyuk ransomware member sentenced to 24 months in prison
HighFrom Payment Plan to Ransomware - Inside a Global Group Attack
HighThe Closed Quorum: Inside the first reported autonomous AI C2 implant
HighAI Agents Are Rewriting the Rules of Lateral Movement
HighMicrosoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises
HighTwo arrested in UK after Microsoft takedown of ‘Eviltokens’ AI-chatbot for cybercriminals
HighNew TASK#STOMP Windows Backdoor Enables Continuous Document Theft
HighA cheap fake base station can still track 5G subscribers
HighSideCopy Broadens India Targeting to Academia With ReverseRAT Spear-Phishing
HighClickFix Attacks Spread ChainScript RAT via Fake Spotify and Teams Installers
HighChina-Linked FamousSparrow Deploys SparroWocky Backdoor in Latin America
HighRogue Behavior: OpenAI Reveals More Model Misalignment Incidents
HighCybercriminals Are Hiding New Malware in Torrents for Popular Films
HighShinyHunters Hacked Clop. Now What About Clop's Victims?
HighHow AI Agents Can Trigger Runaway Costs for Enterprises
HighReverse-Engineering Flock Cameras
HighThe AI models that cheat the most, according to new CAIS benchmark
HighNorth Korea’s job interview scam runs both ways
HighThe TASK#STOMP Windows backdoor takes Wi-Fi passwords, screenshots, and business files
HighTASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data
High⚡ Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacks
HighContagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in Crypto
HighFake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR
HighShinyHunters cybercrime gang takes over Cl0p ransomware site, demands extortion payment
HighCyber Extortion War: ShinyHunters Holds Rival Clop to Ransom
HighGoogle Gemini Agents Access Real Companies in AI Safety Test
HighGemini’s breach of real companies exposes an AI guardrail problem
HighThe fake sites using a cheap toolkit to sell $2,000 AI subscriptions
HighUK Police Data Faces Long-Standing Microsoft Cloud Security Concerns
HighA BYD Shark 6 Hack Shows the Risks of Connected Cars
HighChainScript: the RAT that hides its command server inside a blockchain contract
HighTerminalFix: PNG Steganography, (Mon, Sep 21st)
HighExecution Runtime Security in the Era of Agentic AI
HighFrom Exposure to Lockdown: How AWS Neutralizes Compromised IAM Credentials through Managed Policies
HighAI compliance issues hit 2 in 5 large companies, and legacy workflows are a big factor
HighIntent injection attacks are a new worry for AI-native 6G networks
HighScammers impersonate cops, use arrest threats to extort victims
HighClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure
HighRussia reports thousands of cyberattacks on election infrastructure during vote
MediumSECURITY AFFAIRS AI-CYBERSECURITY NEWSLETTER ROUND 1
MediumAnthropic turns Claude into an AI marketplace with 2,000+ plugins and connectors
Medium7-Year, $11.6B Anthropic Deal Drives Akamai Cloud Buildout
MediumHalf of threat hunters say bad data is their biggest problem
MediumDataiku Agent Management reveals unmonitored AI agents
MediumAbnormal AI brings governance, cloud security, and threat investigation into one suite
MediumLinkedIn adds new checks for fake profiles and work histories
MediumCofense measures employee readiness against real-world phishing threats
MediumWeekly Update 522: Live From Oslo with Scott Helme
MediumWebinar tomorrow: Inside real-world Google Workspace breaches
MediumGPT-6 Astra Breaks an Old Enigma Message
MediumThe next intellectual property thief may sound like your CEO
MediumThe Target Is No Longer the Model. It’s the Agent.
MediumKnow what was tested before your SAP ECC migration goes live
MediumSiemba brings continuous IDOR testing to production APIs
InformationalClaude Opus 5.5 uses 95% fewer em dashes, but its answers are getting longer
InformationalSentinelOne extends Wayfinder coverage across endpoints, identities, and cloud workloads
InformationalOpenAI Expands Outside Safety Reviews Into Model Training
InformationalEmail Makes Up Nearly 1 in 3 MSSP Analyses: How Tier 1 Can Triage Phishing Faster
InformationalNo evidence of successful foreign meddling in 2024 election, spy agencies found
InformationalPhone Hacking Software Firm Hid Russian Ownership, Say Feds
LowDeception by Design: CISA's Guide to Tricking Cybercriminals
InformationalGPT-6 Sol and Luna arrive with 50% lower API prices
InformationalFastly gives enterprises real-time control over AI models and agents

Vulnerability (45)

CriticalCitrix Confirmed Two New NetScaler Flaws Exploited as Zero-Day
CriticalCritical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway
CriticalCitrix confirms two NetScaler RCE zero-days exploited in attacks
CriticalAttackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells
CriticalAttackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure
CriticalWSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV
CriticalEufy Omni C20, Omni X10 Pro
CriticalNew cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control
CriticalCritical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input
CriticalF5 patches BIG-IP APM zero-day flaw exploited in RCE attacks
CriticalCheck Point warns of Management Server zero-day exploited in attacks
CriticallwIP TCP/IP Stack MQTT Client Application
HighWireshark 4.6.9 Released, (Sun, Sep 27th)
HighCloudflare fixes Containers cross-tenant flaw exposing customer data
HighShinyHunters Bypass WAF Rules to Resume Oracle PeopleSoft Attacks
HighSharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild
HighElementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link
HighMultiple Vulnerabilities in ServiceNow's AI Platform Could Allow for Unauthorized Access
HighShinyHunters hacked Clop leak site using Grav CMS path traversal flaw
HighCISA Adds One Known Exploited Vulnerability to Catalog
HighZDI-26-724: Foxit PDF Reader Annotation Use-After-Free Remote Code Execution Vulnerability
HighZDI-26-727: Foxit PDF Reader Annotation Use-After-Free Remote Code Execution Vulnerability
HighZDI-26-730: Foxit PDF Reader DeviceN Colorspace Out-Of-Bounds Write Remote Code Execution Vulnerability
HighZDI-26-733: Foxit PDF Reader Portfolio Directory Traversal Remote Code Execution Vulnerability
HighZDI-26-741: Foxit PDF Reader FoxitUpdater Improper Certificate Validation Local Privilege Escalation Vulnerability
HighZDI-26-742: Foxit PDF Reader FoxitUpdater Race Condition Local Privilege Escalation Vulnerability
HighZDI-26-744: Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability
HighHackers now exploit critical Roundcube flaw in code injection attacks
HighExposed GitLab project email addresses let attackers push code
HighBotslab G980H Dashcams
HighUpdate Chrome: 108 security fixes for desktop, new release for Android
HighHow Cloudflare addressed a cross-tenant data exposure vulnerability in Containers
HighGitLab Email Addresses Can Be Weaponized for Supply Chain Attacks
HighMikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key
HighMedical Imaging Archive Flaws Put Patient Scans at Risk
HighPublic PoC Exposes Critical Veeam Agent Privilege Escalation
HighWordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session
HighNew Windows Defender zero-day blocks Microsoft antivirus updates
HighWordPress Click2Shell flaw lets hackers execute PHP on the server
HighCISA alerts of active exploitation of three Linux kernel flaws
HighCISA Adds One Known Exploited Vulnerability to Catalog
MediumZDI-26-720: Foxit PDF Reader activeDocs Missing Authorization Information Disclosure Vulnerability
MediumZDI-26-732: Foxit PDF Reader importIcon NTLM Response Information Disclosure Vulnerability
MediumZDI-26-739: Foxit PDF Reader Doc Object Out-Of-Bounds Read Information Disclosure Vulnerability
LowZDI-26-726: Foxit PDF Reader Doc Object Use-After-Free Information Disclosure Vulnerability

Daily breach, advisory, and vulnerability briefs publish every weekday.

View Live Breach Feed ← All Weekly Digests