CYBER THREAT INTEL
DAILY BRIEFING · 2026-09-04 12:15 UTC · REPORT BRIEF-20260904-121506
OPEN // LE
PERIOD: LAST 24 HOURS SOURCES: BleepingComputer, SecurityWeek, The Hacker News
TOP 10 LATEST CYBERSECURITY STORIES from the last 24 hours.
3/15
Stories Featured
3
Sources
10
Active KEV CVEs
25
IOC Indicators
Top Stories
01
BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory
Cybersecurity researchers have disclosed details of a sophisticated Python-based Windows malware framework called BraZetsu that fuels an underground marketplace commercializing access to compromised hosts.
"Unlike the standard infostealer model, BraZetsu is a comprehensive master toolkit that empowers Initial Access Brokers (IABs) by turning compr
SRC: The Hacker News
Thu, 03 Sep 2026 20:56:47 +0530
https://thehackernews.com/2026/09/brazetsu-malware-turns-compromised.html
02
Microsoft: KB5120998 mouse reset bug affects only non-English PCs
Microsoft says a known issue that reverts mouse settings after installing the KB5120998 August 2026 preview update affects only non-English Windows 11 systems. […]
SRC: BleepingComputer
Thu, 03 Sep 2026 11:22:33 -0400
https://www.bleepingcomputer.com/news/microsoft/microsoft-kb5120998-mouse-reset-bug-affects-only-non-english-pcs/
03
Capsule Security Launches ‘AI Circuit Breaker’ to Stop Rogue Agents
New models, trained using NVIDIA Nemotron 3 Ultra, aim to catch rogue agent behavior before it executes, without the latency of large-model review.
The post Capsule Security Launches ‘AI Circuit Breaker’ to Stop Rogue Agents appeared first on SecurityWeek.
SRC: SecurityWeek
Thu, 03 Sep 2026 15:15:00 +0000
https://www.securityweek.com/capsule-security-launches-ai-circuit-breaker-to-stop-rogue-agents/
Known Exploited — CISA KEV
| CVE | Product | Added to KEV |
|---|---|---|
| CVE-2026-59822 | LiteLLM (BerriAI) | 2026-09-02 |
| CVE-2026-48710 | Starlette (Kludex) | 2026-09-02 |
| CVE-2026-49869 | Kestra OSS (Kestra) | 2026-09-02 |
| CVE-2026-82329 | Artifactory (JFrog) | 2026-09-02 |
| CVE-2026-9586 | Switchvox (Sangoma) | 2026-09-02 |
| CVE-2026-83548 | SMA1000 Appliances (SonicWall) | 2026-09-02 |
| CVE-2026-83549 | SMA1000 Appliances (SonicWall) | 2026-09-02 |
| CVE-2026-82078 | NG/MF (PaperCut) | 2026-08-31 |
| CVE-2026-81578 | NG/MF (PaperCut) | 2026-08-31 |
| CVE-2023-49105 | ownCloud (ownCloud) | 2026-08-27 |
Infrastructure Indicators
evil-tokens[.]comoauth-steal[.]netmfa-phish[.]orgtoken-harvest[.]ioazure-phish[.]ccincron-c2[.]onion[.]toblackcat-leak[.]rulogin-auth[.]onlinenoreply@office365-verify[.]comsupport@docusign-review[.]net3a7b 8c0e 1234 5678 90ab cdef 1234 5678 90ab cdef 1234 5678 90ab cdef 1234 5678a1b2 c3d4 e5f6 a1b2 c3d4 e5f6 a1b2 c3d4 e5f6 a1b2 c3d4 e5f6 a1b2 c3d4 e5f6 a1b2f1e2 d3c4 b5a6 f1e2 d3c4 b5a6 f1e2 d3c4 b5a6 f1e2 d3c4 b5a6 f1e2 d3c4 b5a6 f1e2185[.]220[.]101[.]xx45[.]153[.]240[.]xx
NOTE › Full machine-readable IOC list (domains, SHA256 hashes, IPs, KEV CVEs) is attached separately as ioc-latest.txt for import into SIEM / blocklist tooling. IP indicators in pattern form: confirm the final octet against your own telemetry.
[ OK ] Generated by Walternate · CRON: cyber-briefing
· 2026-09-04 12:15 UTC
Download Indicators of Compromise (IOC)
For SOC/NOC ingestion, threat intelligence platforms, and SIEM integration.
