CYBER THREAT INTEL
DAILY BRIEFING · 2026-09-16 15:40 UTC · REPORT BRIEF-20260916-154039
OPEN // LE
PERIOD: LAST 24 HOURS SOURCES: Ars Technica Security, BBC Technology, BleepingComputer, BleepingComputer (Google News), Cyber Risk & Security, Cyber Threat Intelligence
TOP 10 LATEST CYBERSECURITY STORIES from the last 24 hours.
18
Stories Featured
54
Sources
10
Active KEV CVEs
28
IOC Indicators
Top Stories
01
Google says some Pixel phone owners were hacked in zero-day attacks
The Pixel phone maker said there are indications that a bug in the phone's modem "may be under limited, targeted exploitation."
SRC: TechCrunch Security
Wed, 16 Sep 2026 14:47:07 +0000
https://techcrunch.com/2026/09/16/google-says-some-pixel-phone-owners-were-hacked-in-zero-day-attacks/
02
Google Patches Pixel Modem Zero-Day Exploited in Targeted Attacks
Google has patched a high-severity zero-day in the Pixel cellular modem after finding evidence that the vulnerability was exploited in limited, targeted attacks. Google has released its September 2026 Pixel security update, addressing a large set of vulnerabilities, including a high-severity flaw, t
SRC: Security Affairs
Wed, 16 Sep 2026 13:43:53 +0000
https://securityaffairs.com/199193/hacking/google-patches-pixel-modem-zero-day-exploited-in-targeted-attacks.html
03
Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories
Mandiant says an attacker hijacked an active AI coding-assistant session at an unnamed software-as-a-service provider and later spread Shai-Hulud across about 100 internal code repositories.
Before the repository spread, the assistant recommended software that the attacker had poisoned, and the rec
SRC: The Hacker News
Wed, 16 Sep 2026 19:07:07 +0530
https://thehackernews.com/2026/09/attacker-hijacks-ai-coding-assistant.html
04
Pixel Modem Zero-Day Exploited in Targeted Attacks
Google announced patches for the exploited privilege escalation vulnerability (CVE-2026-58704) on September 15.
The post Pixel Modem Zero-Day Exploited in Targeted Attacks appeared first on SecurityWeek.
SRC: SecurityWeek
Wed, 16 Sep 2026 13:10:54 +0000
https://www.securityweek.com/pixel-modem-zero-day-exploited-in-targeted-attacks/
05
The true cost of a ransomware attack, with and without BCDR
The ransom itself can be only a fraction of the total cost of a ransomware attack, with downtime, recovery, remediation, and legal obligations adding millions to the bill. Datto explains how a mature BCDR strategy can reduce downtime and provide a faster, more predictable path to recovery. […]
SRC: BleepingComputer
Wed, 16 Sep 2026 10:00:10 -0400
https://www.bleepingcomputer.com/news/security/the-true-cost-of-a-ransomware-attack-with-and-without-bcdr/
06
What’s next for CISA’s CDM program that gives cybersecurity tools to federal agencies
Three feds spoke about future plans for the Continuous Diagnostics and Mitigation program, and lessons they’ve learned.
The post What’s next for CISA’s CDM program that gives cybersecurity tools to federal agencies appeared first on CyberScoop.
SRC: CyberScoop
Tue, 15 Sep 2026 19:45:35 +0000
https://cyberscoop.com/whats-next-for-cisas-cdm-program-that-gives-cybersecurity-tools-to-federal-agencies/
07
EU Chief Warns of AI-Powered Hacking, Moves to Rein In Social Media
Ursula von der Leyen warns that advanced AI could unleash hacking on an unprecedented scale as Europe prepares new protections against social media’s “capture” of children.
The post EU Chief Warns of AI-Powered Hacking, Moves to Rein In Social Media appeared first on SecurityWeek.
SRC: SecurityWeek
Wed, 16 Sep 2026 14:15:18 +0000
https://www.securityweek.com/eu-chief-warns-of-ai-powered-hacking-moves-to-rein-in-social-media/
08
US, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware
US, UK, and Dutch government agencies published a report detailing the malware, and the FBI described the abuse of Telegram for C&C.
The post US, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware appeared first on SecurityWeek.
SRC: SecurityWeek
Wed, 16 Sep 2026 12:00:14 +0000
https://www.securityweek.com/us-uk-dutch-agencies-expose-iranian-chosen-brick-surveillance-malware/
09
Cyber Op Targets South Korean Media & Automotive Sectors
A likely North Korean advanced persistent threat (APT) group used a previously undocumented Linux espionage toolkit to compromise load balancers, gain access to communications, and further exploit networks.
SRC: DarkReading
Wed, 16 Sep 2026 01:00:00 GMT
https://www.darkreading.com/cyberattacks-data-breaches/cyber-south-korean-media-automotive
10
US military says it has launched weapons into space
This is the first public acknowledgment that the U.S. military put a space weapon in Earth's orbit.
SRC: TechCrunch Security
Tue, 15 Sep 2026 17:09:06 +0000
https://techcrunch.com/2026/09/15/us-military-confirms-it-launched-space-weapons-into-earths-orbit/
11
Revolut Data Leak May Trace Back to Compromised Italian Government Accounts
A suspected compromise of an Italian government PEC account may have allowed threat actors to impersonate law enforcement and obtain sensitive data from hundreds of Revolut customers. The Revolut data exposure may be part of a much broader cyber incident involving compromised Italian government infr
SRC: Security Affairs
Wed, 16 Sep 2026 13:09:22 +0000
https://securityaffairs.com/199180/data-breach/revolut-data-leak-may-trace-back-to-compromised-italian-government-accounts.html
12
Webinar: What happens in the first hours of a Google Workspace breach
The first hours after discovering a Google Workspace breach can determine how an incident unfolds. This webinar examines real-world breaches to show which early response decisions can limit the impact and which can make matters worse. […]
SRC: BleepingComputer
Wed, 16 Sep 2026 08:11:19 -0400
https://www.bleepingcomputer.com/news/security/webinar-what-happens-in-the-first-hours-of-a-google-workspace-breach/
13
Threat Intelligence Alone Won't Close the Exploitation Gap
A leaked credential shows up in a criminal marketplace, or a vulnerability gets a disclosure advisory, and either one can be weaponized against a real target before most security teams have triaged the alert. Attackers are combining that kind of intelligence with AI-assisted exploitation to accelera
SRC: The Hacker News
Wed, 16 Sep 2026 16:45:48 +0530
https://thehackernews.com/2026/09/threat-intelligence-alone-wont-close.html
14
280,000 Impacted by Premier Medical Group Data Breach
In June 2026, hackers accessed files containing patients’ names, contact information, diagnosis details, and health insurance information.
The post 280,000 Impacted by Premier Medical Group Data Breach appeared first on SecurityWeek.
SRC: SecurityWeek
Wed, 16 Sep 2026 10:47:18 +0000
https://www.securityweek.com/280000-impacted-by-premier-medical-group-data-breach/
15
Coast Guard, FBI board US-bound foreign ships in order to probe for cyberattacks
The agencies issued a joint statement saying the “joint security boardings” came in response to “indications that the networks of both vessels were compromised.”
The post Coast Guard, FBI board US-bound foreign ships in order to probe for cyberattacks appeared first on CyberScoop.
SRC: CyberScoop
Wed, 16 Sep 2026 14:48:07 +0000
https://cyberscoop.com/coast-guard-fbi-investigate-tanker-cyberattacks/
16
Virtual Event Today: Attack Surface Management Summit
Join SecurityWeek today for a virtual summit exploring the strategies and tools organizations need to discover, prioritize, and defend their expanding attack surfaces.
The post Virtual Event Today: Attack Surface Management Summit appeared first on SecurityWeek.
SRC: SecurityWeek
Wed, 16 Sep 2026 14:35:04 +0000
https://www.securityweek.com/virtual-event-today-attack-surface-management-summit-2/
17
Treasury’s Scott Bessent says no liability exemptions for AI labs
The secretary told House Financial Services Committee lawmakers that the “best way to guarantee safety” is for AI creators to be held “liable for what they build and generate.”
The post Treasury’s Scott Bessent says no liability exemptions for AI labs appeared first on CyberScoop.
SRC: CyberScoop
Wed, 16 Sep 2026 14:10:19 +0000
https://fedscoop.com/treasury-scott-bessent-ai-labs-liability-exemptions/
18
AIUC Raises $40 Million to Certify Enterprise AI Agents
The company provides a standard for AI systems, testing them against risks such as jailbreaks, prompt injections, and unauthorized actions.
The post AIUC Raises $40 Million to Certify Enterprise AI Agents appeared first on SecurityWeek.
SRC: SecurityWeek
Wed, 16 Sep 2026 13:38:36 +0000
https://www.securityweek.com/aiuc-raises-40-million-to-certify-enterprise-ai-agents/
Known Exploited — CISA KEV
| CVE | Product | Added to KEV |
|---|---|---|
| CVE-2026-58704 | Pixel (Google) | 2026-09-16 |
| CVE-2026-76461 | Secure Email Gateway (Cisco) | 2026-09-14 |
| CVE-2026-84869 | ScreenConnect (ConnectWise) | 2026-09-11 |
| CVE-2026-42016 | Artifactory (JFrog) | 2026-09-11 |
| CVE-2026-42018 | Artifactory (JFrog) | 2026-09-11 |
| CVE-2026-85706 | Community Edition and Enterprise Edition (GitLab) | 2026-09-11 |
| CVE-2026-86060 | RouterOS (MikroTik) | 2026-09-10 |
| CVE-2026-67277 | RouterOS (MikroTik) | 2026-09-10 |
| CVE-2026-19490 | NetScaler (Citrix) | 2026-09-09 |
| CVE-2025-25249 | Multiple Products (Fortinet) | 2026-09-09 |
Indicators of Compromise (IOC)
Download Indicators of Compromise (IOC)
For SOC/NOC ingestion, threat intelligence platforms, and SIEM integration.
