CYBER THREAT INTEL
DAILY BRIEFING · 2026-09-14 12:15 UTC · REPORT BRIEF-20260914-121515
OPEN // LE
PERIOD: LAST 24 HOURS SOURCES: BleepingComputer, The Hacker News, KrebsOnSecurity
TOP 10 LATEST CYBERSECURITY STORIES from the last 24 hours.
4
Stories Featured
3
Sources
10
Active KEV CVEs
28
IOC Indicators
Top Stories
01
CISA: Hackers Now Exploit Max-Severity GitLab Flaw in Attacks
CISA has warned that threat actors are actively exploiting CVE-2026-85706, a CVSS 10.0 path traversal vulnerability in GitLab's repository commits API that allows unauthenticated file read access. The agency has added the flaw to its Known Exploited Vulnerabilities catalog, underscoring the immediacy of the threat to self-hosted GitLab deployments.
SRC: BleepingComputer
2026-09-14T03:06:27-04:00
https://www.bleepingcomputer.com/news/security/cisa-hackers-now-exploit-max-severity-gitlab-flaw-in-attacks/
02
Hackers Exploit Tencent Sogou Input Method to Deploy GrayRabbit Backdoor
A China-aligned espionage group is exploiting CVE-2026-51990, a critical vulnerability in Tencent's Sogou Input Method for Windows, to deploy the GrayRabbit backdoor. The flaw allows remote code execution through a crafted link, giving the attacker full control of the victim's system. Sogou is used by millions of Chinese PC users.
SRC: BleepingComputer
2026-09-13T10:26:32-04:00
https://www.bleepingcomputer.com/news/security/hackers-exploit-tencent-app-flaw-to-deploy-grayrabbit-malware/
03
Revolut Discloses Data Breach Exposing Financial Info and Passports
Fintech company Revolut disclosed a data breach after sharing customer data with a threat actor impersonating a government agency. The breach exposed financial information and passport data from an undisclosed number of customers, highlighting the growing sophistication of government impersonation attacks targeting financial institutions.
SRC: BleepingComputer
2026-09-14T04:48:24-04:00
https://www.bleepingcomputer.com/news/security/revolut-discloses-data-breach-exposing-financial-info-passports/
04
Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users
A malicious cross-store Twitch browser extension named 'Twitch Enhanced Viewer | JeetBot' has leaked OAuth tokens associated with nearly 31,000 users to proxy servers operated by a Russian commercial bot service. The extension was available on both Chrome Web Store and Firefox Add-Ons, listing HISHIMIRO/jeetbot.cc as its developer.
SRC: The Hacker News
2026-09-14T12:54:39+05:30
https://thehackernews.com/2026/09/malicious-twitch-browser-extension.html
Known Exploited — CISA KEV
| CVE | Product | Added to KEV |
|---|---|---|
| CVE-2026-84869 | ScreenConnect (ConnectWise) | 2026-09-11 |
| CVE-2026-42016 | Artifactory (JFrog) | 2026-09-11 |
| CVE-2026-42018 | Artifactory (JFrog) | 2026-09-11 |
| CVE-2026-85706 | Community Edition and Enterprise Edition (GitLab) | 2026-09-11 |
| CVE-2026-86060 | RouterOS (MikroTik) | 2026-09-10 |
| CVE-2026-67277 | RouterOS (MikroTik) | 2026-09-10 |
| CVE-2026-19490 | NetScaler (Citrix) | 2026-09-09 |
| CVE-2025-25249 | Multiple Products (Fortinet) | 2026-09-09 |
| CVE-2026-87491 | Chromium V8 (Google) | 2026-09-09 |
| CVE-2026-20079 | Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management (Cisco) | 2026-09-09 |
Indicators of Compromise (IOC)
Download Indicators of Compromise (IOC)
For SOC/NOC ingestion, threat intelligence platforms, and SIEM integration.
