CYBER THREAT INTEL
DAILY BRIEFING · 2026-09-10 12:15 UTC · REPORT BRIEF-20260910-121536
OPEN // LE
PERIOD: LAST 24 HOURS SOURCES: Ars Technica, BleepingComputer, Cyber Risk & Security, CyberScoop, DarkReading, Help Net Security
TOP 10 LATEST CYBERSECURITY STORIES from the last 24 hours.
3
Stories Featured
15
Sources
10
Active KEV CVEs
28
IOC Indicators
Top Stories
01
CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline
CISA added three flaws impacting Cisco, Citrix, and Fortinet to its Known Exploited Vulnerabilities catalog, requiring federal agencies to patch by September 12. The additions underscore the urgency for organizations to remediate actively exploited vulnerabilities across networking and secure communications infrastructure.
SRC: The Hacker News
Thu, 10 Sep 2026 16:06:46 +0530
https://thehackernews.com/2026/09/cisa-flags-exploited-cisco-citrix.html
02
Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA
Cybercriminals are hijacking AI user accounts via information stealer logs to create 'stolen keys' that grant illicit access to tools from model providers including Google and Anthropic. The stolen keys can bypass multi-factor authentication and replayable tokens are being sold on underground forums.
SRC: The Hacker News
Wed, 09 Sep 2026 19:53:55 +0530
https://thehackernews.com/2026/09/infostealer-logs-expose-replayable-ai.html
03
Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week
Multiple espionage-motivated threat activity clusters have been found deploying a previously undocumented exploit kit called BlueMoon, chaining multiple vulnerabilities in Microsoft Windows and Google Chrome browsers. The coordination across at least four state-sponsored or spyware groups highlights shared infrastructure and techniques in advanced persistent threat operations.
SRC: The Hacker News
Wed, 09 Sep 2026 22:04:05 +0530
https://thehackernews.com/2026/09/four-spy-groups-used-same-chrome-and.html
Known Exploited — CISA KEV
| CVE | Product | Added to KEV |
|---|---|---|
| CVE-2026-19490 | NetScaler (Citrix) | 2026-09-09 |
| CVE-2025-25249 | Multiple Products (Fortinet) | 2026-09-09 |
| CVE-2026-87491 | Chromium V8 (Google) | 2026-09-09 |
| CVE-2026-20079 | Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management (Cisco) | 2026-09-09 |
| CVE-2026-75650 | Commerce and Magento (Adobe) | 2026-09-08 |
| CVE-2026-81963 | Windows (Microsoft) | 2026-09-08 |
| CVE-2026-86218 | N-central (N-able) | 2026-09-08 |
| CVE-2026-85880 | Windows (Microsoft) | 2026-09-08 |
| CVE-2026-85046 | Chromium V8 (Google) | 2026-09-04 |
| CVE-2026-59822 | LiteLLM (BerriAI) | 2026-09-02 |
Indicators of Compromise (IOC)
Download Indicators of Compromise (IOC)
For SOC/NOC ingestion, threat intelligence platforms, and SIEM integration.
