CYBER THREAT INTEL
DAILY BRIEFING · 2026-09-15 12:15 UTC · REPORT BRIEF-20260915-121539
OPEN // LE
PERIOD: LAST 24 HOURS SOURCES: Bleeping Computer, CSO Online, Cyberscoop, Krebs on Security, Securelist, Security Affairs
TOP 10 LATEST CYBERSECURITY STORIES from the last 24 hours.
15
Stories Featured
8
Sources
10
Active KEV CVEs
28
IOC Indicators
Top Stories
01
240,000 Hit by Data Breach at Japan’s Digital Agency
Hackers exploited a vulnerability in a VPN product to steal the personal information of roughly 240,000 people. The post 240,000 Hit by Data Breach at Japan s Digital Agency appeared first on SecurityWeek.
SRC: Security Week
Tue, 15 Sep 2026 11:45:31 +0000
https://www.securityweek.com/240000-hit-by-data-breach-at-japans-digital-agency/
02
Apple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 Releases
The updates resolve kernel vulnerabilities that could lead to memory corruption, privilege escalation, system termination, and information leaks. The post Apple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 Releases appeared first on SecurityWeek.
SRC: Security Week
Tue, 15 Sep 2026 11:06:11 +0000
https://www.securityweek.com/apple-patches-200-vulnerabilities-with-new-ios-27-macos-golden-gate-27-releases/
03
One Exploit Chain, Two Espionage Campaigns: Chrome and Windows Under Fire
Two China-linked groups ran identical Chrome/Windows zero-day exploits against NGOs, before Chrome s patch shipped, deploying different backdoors each. Two China-linked threat actors used the same Chrome/Windows zero-day against NGOs starting September 1, 2026, Volexity s new report lays out the whole chain in detail. On September 1, Volexity detected a spear-phishing campaign by UTA0560 targeting several [ ]
SRC: Security Affairs
Tue, 15 Sep 2026 10:17:40 +0000
https://securityaffairs.com/199104/apt/one-exploit-chain-two-espionage-campaigns-chrome-and-windows-under-fire.html
04
Threat actors are coming for your AI assets to operationalize their use of AI
Both state-affiliated cyberespionage group and cybercrime gangs are targeting AI-related documents, configuration files, and proprietary models during intrusions. In addition, the number and scope of distillation attacks, where the knowledge, logic, and reasoning capabilities of LLMs is being extracted with targeted prompts, is increasing. “GTIG observed adversaries with wide-ranging motivations target proprietary AI models and source code, exfiltrate application programming interface (API) credentials, and co-opt victim cloud environments to sustain unauthorized AI workloads,” the Google Threat Intelligence Group (GTIG), said in their latest quarterly AI Threat Tracker report released last week.
SRC: CSO Online
Tue, 15 Sep 2026 08:25:00 +0000
https://www.csoonline.com/article/4221307/threat-actors-are-coming-for-your-ai-assets-to-operationalize-their-use-of-ai.html
05
Telegram Desktop Flaw Could Turn Old Chat Exports Into Data Theft Traps
A Telegram Desktop flaw let bots inject JavaScript into exported chats, enabling data theft and page manipulation. Old HTML exports remain unsafe. A vulnerability in Telegram Desktop could have turned an ordinary chat export into a serious data leak.
SRC: Security Affairs
Tue, 15 Sep 2026 07:48:52 +0000
https://securityaffairs.com/199076/security/telegram-desktop-flaw-could-turn-old-chat-exports-into-data-theft-traps.html
06
Cisco patches Secure Email Gateway zero-day exploited in attacks
Cisco warned customers to patch a critical Secure Email Gateway zero-day security flaw that threat actors have been exploiting in attacks. […]
SRC: Bleeping Computer
Tue, 15 Sep 2026 03:31:09 -0400
https://www.bleepingcomputer.com/news/security/new-cisco-secure-email-zero-day-exploited-to-execute-commands-as-root/
07
Non-Zero-Day VPN Flaw Left Japan ‘s Government Shared Network Platform Exposed: 246,000 Records at Risk
Japan s Digital Agency disclosed a VPN breach exposing 246,000 government employee records across 23 ministries. Detected June 25, publicly disclosed September 11. Japan s Digital Agency disclosed that attackers exploited a vulnerability in a VPN device to access its Government Solution Service (GSS), potentially leaking personal information belonging to approximately 246,000 government employees, public [ ]
SRC: Security Affairs
Tue, 15 Sep 2026 07:19:25 +0000
https://securityaffairs.com/199090/security/non-zero-day-vpn-flaw-left-japan-government-shared-network-platform-exposed-246000-records-at-risk.html
08
LiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access on a Shared Server
A critical vulnerability in LiteSpeed Web Server Enterprise could let a low-privilege website user gain root access on a shared-hosting server, cPanel warned in an advisory published on September 14. On such servers, many customers' sites run on a single machine, and an attacker with one of those hosting accounts could exploit the flaw to access or alter other sites and the server itself,
SRC: The Hacker News
Tue, 15 Sep 2026 12:22:16 +0530
https://thehackernews.com/2026/09/litespeed-enterprise-flaw-could-let-one.html
09
Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution
Cisco has warned that a new critical vulnerability impacting AsyncOS Software for Cisco Secure Email Gateway has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-76461, carries a CVSS score of 9.8 out of a maximum of 10.0. It has been described as a case of insufficient validation in the email parsing logic that could allow an unauthenticated, remote attacker
SRC: The Hacker News
Tue, 15 Sep 2026 11:41:11 +0530
https://thehackernews.com/2026/09/cisco-secure-email-gateway-flaw.html
10
China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE
A Chinese threat actor has been attributed to a spear-phishing campaign that exploits recently patched security flaws in Google Chrome and Microsoft Windows to deliver a malicious JavaScript backdoor called GRIMWEDGE. Volexity, which is tracking the threat cluster under the moniker UTA0560, said the activity targeted multiple non-governmental organizations (NGOs) on September 1, 2026. "The
SRC: The Hacker News
Tue, 15 Sep 2026 11:01:05 +0530
https://thehackernews.com/2026/09/china-linked-hackers-exploit-chrome.html
11
AI is exposing a security structure built for yesterday’s threats
Organizations are investing more in security than ever before, yet many still struggle with a fundamental problem: they are preparing for tomorrow’s crisis with yesterday’s mindset. For decades, companies organized security around neat categories. Cybersecurity protected networks.
SRC: CSO Online
Tue, 15 Sep 2026 09:00:00 +0000
https://www.csoonline.com/article/4221801/ai-is-exposing-a-security-structure-built-for-yesterdays-threats.html
12
Suspected Black Axe gang leaders face cybercrime charges in the US
Five alleged leaders of the Black Axe cybercrime syndicate, known for its involvement in global-scale cyber-enabled financial fraud, have been extradited to the United States to face wire fraud and money laundering charges. […]
SRC: Bleeping Computer
Tue, 15 Sep 2026 05:50:25 -0400
https://www.bleepingcomputer.com/news/security/black-axe-gang-members-extradited-to-us-face-cybercrime-charges/
13
Microsoft AI Code of Conduct Sets Cyberattack Boundaries, Chain of Command, Safety Constraints
The Humanist AI Code of Conduct draws a line between defensive cyber research and operational attack capability. The post Microsoft AI Code of Conduct Sets Cyberattack Boundaries, Chain of Command, Safety Constraints appeared first on SecurityWeek.
SRC: Security Week
Tue, 15 Sep 2026 09:40:25 +0000
https://www.securityweek.com/microsoft-ai-code-of-conduct-sets-cyberattack-boundaries-chain-of-command-safety-constraints/
14
Hacked HBO Max Reddit Account Used for Malware Delivery via ClickFix Attack
Ads led to a ClickFix page designed to trick macOS and Windows users into installing malware. The post Hacked HBO Max Reddit Account Used for Malware Delivery via ClickFix Attack appeared first on SecurityWeek.
SRC: Security Week
Tue, 15 Sep 2026 09:09:00 +0000
https://www.securityweek.com/hacked-hbo-reddit-account-used-for-malware-delivery-via-clickfix-attack/
15
Microsoft confirms KB5002914 Excel update breaks copy and paste
Microsoft has confirmed that copy and paste may silently fail for some Excel users after installing the September 2026 KB5002914 security update. […]
SRC: Bleeping Computer
Tue, 15 Sep 2026 04:40:20 -0400
https://www.bleepingcomputer.com/news/microsoft/microsoft-september-kb5002914-security-update-breaks-excel-copy-and-paste/
Known Exploited — CISA KEV
| CVE | Product | Added to KEV |
|---|---|---|
| CVE-2026-76461 | Secure Email Gateway (Cisco) | 2026-09-14 |
| CVE-2026-84869 | ScreenConnect (ConnectWise) | 2026-09-11 |
| CVE-2026-42016 | Artifactory (JFrog) | 2026-09-11 |
| CVE-2026-42018 | Artifactory (JFrog) | 2026-09-11 |
| CVE-2026-85706 | Community Edition and Enterprise Edition (GitLab) | 2026-09-11 |
| CVE-2026-86060 | RouterOS (MikroTik) | 2026-09-10 |
| CVE-2026-67277 | RouterOS (MikroTik) | 2026-09-10 |
| CVE-2026-19490 | NetScaler (Citrix) | 2026-09-09 |
| CVE-2025-25249 | Multiple Products (Fortinet) | 2026-09-09 |
| CVE-2026-87491 | Chromium V8 (Google) | 2026-09-09 |
Indicators of Compromise (IOC)
Download Indicators of Compromise (IOC)
For SOC/NOC ingestion, threat intelligence platforms, and SIEM integration.
