CYBER THREAT INTEL
DAILY BRIEFING · 2026-09-12 15:19 UTC · REPORT BRIEF-20260912-151916
OPEN // LE
PERIOD: LAST 24 HOURS SOURCES: Ars Technica Security, BBC Technology, BleepingComputer, BleepingComputer (Google News), Cyber Risk & Security, Cyber Threat Intelligence
TOP 10 LATEST CYBERSECURITY STORIES from the last 24 hours.
17
Stories Featured
54
Sources
10
Active KEV CVEs
28
IOC Indicators
Top Stories
01
Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent
The Dutch Nationaal Cyber Security Centrum (NCSC) is warning of imminent exploitation of two critical flaws in Check Point VPN tracked as CVE-2026-85102 and CVE-2026-85103. […]
SRC: BleepingComputer
Sat, 12 Sep 2026 10:14:32 -0400
https://www.bleepingcomputer.com/news/security/dutch-ncsc-critical-check-point-vpn-flaws-exploitation-is-imminent/
02
BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days
Multiple espionage-motivated threat actors have adopted BlueMoon in opportunistic, rushed deployments.
The post BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days appeared first on SecurityWeek.
SRC: SecurityWeek
Sat, 12 Sep 2026 11:10:00 +0000
https://www.securityweek.com/bluemoon-exploit-kit-chains-recent-chrome-windows-zero-days/
03
Papercut AI Swarm Attack Heralds Changes for Cyber Kill Chain
From creating lab environments for staging and testing agentic attacks to reconnaissance to lateral movement and exfiltration, the most innovative attackers are widely incorporating AI.
SRC: DarkReading
Fri, 11 Sep 2026 15:48:27 GMT
https://www.darkreading.com/cyberattacks-data-breaches/papercut-ai-swarm-attack-cyber-kill-chain
04
GitLab’s critical flaw is already drawing internet-wide probes
One flaw allows an unauthenticated attacker to read files from the server. GitLab urged operators of self-managed installations to upgrade immediately.
The post GitLab’s critical flaw is already drawing internet-wide probes appeared first on CyberScoop.
SRC: CyberScoop
Fri, 11 Sep 2026 18:41:52 +0000
https://cyberscoop.com/gitlab-critical-flaws-path-traversal-scans/
05
Hackers abused Claude to extract secrets from 1.8M Android apps
Anthropic says multiple threat groups, including the financially motivated and state-sponsored espionage groups linked to Russia and China, tried to abuse its Claude AI model for malicious purposes. […]
SRC: BleepingComputer
Fri, 11 Sep 2026 16:19:09 -0400
https://www.bleepingcomputer.com/news/security/hackers-abused-claude-to-extract-secrets-from-18m-android-apps/
06
Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks
Anthropic on Thursday said it identified and disrupted industrial-scale illicit distillation attacks against Claude from seven labs based in China, including Alibaba, Moonshot, DeepSeek, Z.ai (aka Zhipu), and MiniMax.
Knowledge distillation by itself is a legitimate training method. It refers to a
SRC: The Hacker News
Fri, 11 Sep 2026 21:45:29 +0530
https://thehackernews.com/2026/09/anthropic-says-seven-china-based-ai.html
07
Revolut confirms customer data breach through fake government requests
Revolut said it notified affected customers and alerted the relevant government agency, law enforcement, and financial regulators.
SRC: TechCrunch Security
Sat, 12 Sep 2026 14:40:00 +0000
https://techcrunch.com/2026/09/12/revolut-confirms-customer-data-breach-through-fake-government-requests/
08
CISA Calls for More Guidance, Less Spin, as Cyber Outages Escalate
A new joint government advisory signals a regulatory shift, pressing organizations to adopt more transparent breach notification and incident response protocols.
SRC: DarkReading
Fri, 11 Sep 2026 18:44:03 GMT
https://www.darkreading.com/cyber-risk/cisa-calls-for-more-guidance-less-spin-as-cyber-outages-escalate
09
Florida confirms DMV database breached via stolen police account
The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has confirmed that its DAVID driver database suffered a data breach, saying the attackers gained access using credentials belonging to a police department employee. […]
SRC: BleepingComputer
Fri, 11 Sep 2026 15:00:29 -0400
https://www.bleepingcomputer.com/news/security/florida-confirms-dmv-database-breached-via-stolen-police-account/
10
Passkey-themed phishing attacks lead to Microsoft 365 data theft
Microsoft says threat actors linked to ShinyHunters, Helix, and other extortion gangs are using passkey and single sign-on-themed social engineering attacks to compromise corporate Microsoft accounts and steal data from Microsoft 365 services. […]
SRC: BleepingComputer
Fri, 11 Sep 2026 13:26:50 -0400
https://www.bleepingcomputer.com/news/security/passkey-themed-phishing-attacks-lead-to-microsoft-365-data-theft/
11
OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers
The "major malicious attack" that targeted RubyGems in May 2026 was the work of a swarm of OpenAI agents, according to a new report published by researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx.
On May 12, Maciej Mensfeld, senior product manager for software supply chain security at Men
SRC: The Hacker News
Sat, 12 Sep 2026 14:37:56 +0530
https://thehackernews.com/2026/09/openai-agents-linked-to-rubygems.html
12
Why AI Is So Good at Scamming Humans
Fred Heiding of Menlo Park Intelligence talks with the Dark Reading News Desk about his research on frontier models, and their ability to influence human behavior and create emotional dependency.
SRC: DarkReading
Fri, 11 Sep 2026 18:14:06 GMT
https://www.darkreading.com/cyber-risk/ai-scamming-humans
13
The AI Supply Chain Has a Security Problem, and Much of It Is Sitting on the Open Internet
Researchers found 36,769 exposed AI endpoints, but only 2% had an HTTP authentication gate. Running AI locally is supposed to give organizations more control. Models, prompts and documents stay on infrastructure they manage instead of being sent to a third-party cloud. But that advantage disappears
SRC: Security Affairs
Fri, 11 Sep 2026 17:27:25 +0000
https://securityaffairs.com/198898/ai/the-ai-supply-chain-has-a-security-problem-and-much-of-it-is-sitting-on-the-open-internet.html
14
When the Whole Company Adopts AI: What It Does to Your SOC
Over the past year, we watched a new class of alert appear in enterprise security operations centers and grow faster than anything else in the stream: alerts that were triggered by AI tools and agents. Not attacks against AI, but the ordinary, everyday footprint of an organization using it, from dev
SRC: The Hacker News
Sat, 12 Sep 2026 15:54:44 +0530
https://thehackernews.com/2026/09/when-whole-company-adopts-ai-what-it.html
15
Users in Houthi-Held Yemen Tried to Develop Advanced Weapons With AI, Anthropic Says
Anthropic said the users did not succeed in “fielding an operational device” but did carry out a failed test of a guided rocket.
The post Users in Houthi-Held Yemen Tried to Develop Advanced Weapons With AI, Anthropic Says appeared first on SecurityWeek.
SRC: SecurityWeek
Sat, 12 Sep 2026 01:50:53 +0000
https://www.securityweek.com/users-in-houthi-held-yemen-tried-to-develop-advanced-weapons-with-ai-anthropic-says/
16
Researchers say OpenAI agents were behind May hacking campaign targeting RubyGems
OpenAI confirmed their agents were behind a campaign in May that researchers say flooded the popular online code repository with malicious software packages.
The post Researchers say OpenAI agents were behind May hacking campaign targeting RubyGems appeared first on CyberScoop.
SRC: CyberScoop
Sat, 12 Sep 2026 01:50:30 +0000
https://cyberscoop.com/openai-agents-malicious-rubygems-packages/
17
Threat Actor Generates 1M Personalized Fraud Emails in 3 Days
Cybercriminals behind malicious email campaigns no longer have to compromise volume for credibility, or vice versa, thanks to AI.
SRC: DarkReading
Fri, 11 Sep 2026 19:21:08 GMT
https://www.darkreading.com/cyberattacks-data-breaches/1m-personalized-fraud-emails-3-days
Known Exploited — CISA KEV
| CVE | Product | Added to KEV |
|---|---|---|
| CVE-2026-84869 | ScreenConnect (ConnectWise) | 2026-09-11 |
| CVE-2026-42016 | Artifactory (JFrog) | 2026-09-11 |
| CVE-2026-42018 | Artifactory (JFrog) | 2026-09-11 |
| CVE-2026-85706 | Community Edition and Enterprise Edition (GitLab) | 2026-09-11 |
| CVE-2026-86060 | RouterOS (MikroTik) | 2026-09-10 |
| CVE-2026-67277 | RouterOS (MikroTik) | 2026-09-10 |
| CVE-2026-19490 | NetScaler (Citrix) | 2026-09-09 |
| CVE-2025-25249 | Multiple Products (Fortinet) | 2026-09-09 |
| CVE-2026-87491 | Chromium V8 (Google) | 2026-09-09 |
| CVE-2026-20079 | Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management (Cisco) | 2026-09-09 |
Indicators of Compromise (IOC)
Download Indicators of Compromise (IOC)
For SOC/NOC ingestion, threat intelligence platforms, and SIEM integration.
