CYBER THREAT INTEL
DAILY BRIEFING · 2026-09-17 12:15 UTC · REPORT BRIEF-20260917-121527
OPEN // LE
PERIOD: LAST 24 HOURS SOURCES: Ars Technica Security, BBC Technology, BleepingComputer, BleepingComputer (Google News), Cyber Risk & Security, Cyber Threat Intelligence
TOP 10 LATEST CYBERSECURITY STORIES from the last 24 hours.
18
Stories Featured
55
Sources
10
Active KEV CVEs
28
IOC Indicators
Top Stories
01
U.S. CISA adds Acronis Backup, Cisco ISE, and Google Pixel flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Acronis Backup, Cisco ISE, and Google Pixel flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added [1, 2] the following vulnerabilities to its Known Exploited Vulne
SRC: Security Affairs
Thu, 17 Sep 2026 09:26:14 +0000
https://securityaffairs.com/199239/security/u-s-cisa-adds-acronis-backup-cisco-ise-and-google-pixel-flaws-to-its-known-exploited-vulnerabilities-catalog.html
02
CISA Releases Cyber Decoy Guidance to Strengthen Critical Infrastructure Defenses
Complementing Zero Trust models, decoys enable organizations to detect, observe, and block malicious activity in their environments.
The post CISA Releases Cyber Decoy Guidance to Strengthen Critical Infrastructure Defenses appeared first on SecurityWeek.
SRC: SecurityWeek
Thu, 17 Sep 2026 07:53:43 +0000
https://www.securityweek.com/cisa-releases-guidance-on-deploying-cyber-decoys/
03
Cisco warns of max severity ISE zero-day exploited in attacks
Cisco has released security updates to address a maximum-severity Identity Services Engine vulnerability that attackers are actively exploiting in the wild. […]
SRC: BleepingComputer
Thu, 17 Sep 2026 03:20:54 -0400
https://www.bleepingcomputer.com/news/security/cisco-warns-of-identity-service-engine-zero-day-exploited-in-attacks/
04
Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day
Remote, unauthenticated attackers can exploit the vulnerability to bypass authentication via crafted requests.
The post Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day appeared first on SecurityWeek.
SRC: SecurityWeek
Thu, 17 Sep 2026 06:19:52 +0000
https://www.securityweek.com/active-exploitation-triggers-emergency-patch-for-cisco-ise-zero-day/
05
Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers
Enterprises in Russia have emerged as the target of three threat activity clusters tracked as NightEagle, Hacking Cat, and Toy Ghouls, according to multiple reports from Kaspersky.
The cybersecurity vendor said it has identified attacks mounted by NightEagle (aka APT-Q-95), a threat actor known to
SRC: The Hacker News
Wed, 16 Sep 2026 20:57:49 +0530
https://thehackernews.com/2026/09/three-threat-groups-target-russian.html
06
The true cost of a ransomware attack, with and without BCDR
The ransom itself can be only a fraction of the total cost of a ransomware attack, with downtime, recovery, remediation, and legal obligations adding millions to the bill. Datto explains how a mature BCDR strategy can reduce downtime and provide a faster, more predictable path to recovery. […]
SRC: BleepingComputer
Wed, 16 Sep 2026 10:00:10 -0400
https://www.bleepingcomputer.com/news/security/the-true-cost-of-a-ransomware-attack-with-and-without-bcdr/
07
America’s cyber strategy overlooks the infrastructure that actually keeps the military moving
Ports, railroads, and utilities keep the military operational. They're all vulnerable to Iranian cyberattacks.
The post America’s cyber strategy overlooks the infrastructure that actually keeps the military moving appeared first on CyberScoop.
SRC: CyberScoop
Thu, 17 Sep 2026 10:00:00 +0000
https://cyberscoop.com/us-cyber-strategy-iranian-threats-infrastructure-op-ed/
08
Chinese hackers use SparroWocky malware in govt espionage attacks
The China-linked espionage group FamousSparrow has been using a new backdoor named SparroWocky in attacks on government organizations in Latin America. […]
SRC: BleepingComputer
Thu, 17 Sep 2026 05:00:00 -0400
https://www.bleepingcomputer.com/news/security/chinese-hackers-use-sparrowocky-malware-in-govt-espionage-attacks/
09
Chosen Brick, Iran’s Surveillance Malware
UK, US, and Dutch agencies expose Chosen Brick, Iranian malware used to track and harass dissidents, journalists, and activists via Telegram. The UK, the US, and the Netherlands published a joint advisory warning about a Windows malware family, dubbed Chosen Brick, that Iran’s intelligence services
SRC: Security Affairs
Thu, 17 Sep 2026 07:25:27 +0000
https://securityaffairs.com/199217/malware/chosen-brick-irans-surveillance-malware.html
10
Iranian hackers use CHOSEN BRICK Windows malware to spy on targets
Government agencies are warning that Iranian state-linked hackers are using a Windows malware strain named CHOSEN BRICK to target dissidents, activists, and journalists worldwide. […]
SRC: BleepingComputer
Wed, 16 Sep 2026 16:24:55 -0400
https://www.bleepingcomputer.com/news/security/iranian-hackers-use-chosen-brick-windows-malware-to-spy-on-targets/
11
Microsoft shares workaround for Windows domain login issues
Microsoft shared a temporary fix on Wednesday for a known issue that prevents Windows 11 users from logging in with valid domain credentials after installing the September 2026 security updates. […]
SRC: BleepingComputer
Thu, 17 Sep 2026 04:24:48 -0400
https://www.bleepingcomputer.com/news/microsoft/microsoft-releases-workaround-for-windows-domain-login-authentication-issues/
12
AI Agents Can Retrain Own Models Mid-Task, Leaking Secrets and Erasing Refusals
New research from Irregular shows AI agents can retrain and redeploy their own underlying models during routine maintenance tasks.
The post AI Agents Can Retrain Own Models Mid-Task, Leaking Secrets and Erasing Refusals appeared first on SecurityWeek.
SRC: SecurityWeek
Thu, 17 Sep 2026 07:41:29 +0000
https://www.securityweek.com/ai-agents-can-retrain-own-models-mid-task-leaking-secrets-and-erasing-refusals/
13
Windows 11 KB5124008 update breaks domain trust for some users
Microsoft is investigating reports that the Windows 11 KB5124008 security update is breaking domain trust relationships on some enterprise systems, preventing users from logging in with valid domain credentials. […]
SRC: BleepingComputer
Wed, 16 Sep 2026 16:39:29 -0400
https://www.bleepingcomputer.com/news/microsoft/windows-11-kb5124008-update-breaks-domain-trust-for-some-users/
14
Malware bypasses browser checks to force install Chrome, Edge extensions
A banking malware operation active since mid-2025 has been using a toolkit named KREMLIN to install malicious Chrome and Edge extensions that steal credentials, session tokens, and sensitive data. […]
SRC: BleepingComputer
Wed, 16 Sep 2026 14:50:53 -0400
https://www.bleepingcomputer.com/news/security/malware-bypasses-browser-checks-to-force-install-chrome-edge-extensions/
15
NightmareStresser Goes Offline in Global DDoS-for-Hire Crackdown
The DOJ seized domains behind NightmareStresser, a DDoS-for-hire service tied to hundreds of thousands of attacks since 2022, as part of Operation PowerOFF. Renting a DDoS attack used to be as easy as renting a movie. Pick a target, pay a few dollars, watch the site go dark. The Justice Department j
SRC: Security Affairs
Thu, 17 Sep 2026 11:35:13 +0000
https://securityaffairs.com/199251/cyber-crime/nightmarestresser-goes-offline-in-global-ddos-for-hire-crackdown.html
16
US takes down NightmareStresser DDoS-for-hire platform
The U.S. Federal Bureau of Investigation (FBI) seized the domains used by NightmareStresser, one of the world's longest-running distributed denial-of-service (DDoS) platforms. […]
SRC: BleepingComputer
Thu, 17 Sep 2026 07:33:35 -0400
https://www.bleepingcomputer.com/news/security/fbi-seizes-nightmarestresser-service-linked-to-thousands-of-ddos-attacks/
17
AI Security Spending Jumps as Fear Outpaces Proof of Value
CISOs are not waiting for AI to prove its cybersecurity value before investing in the technology. Is it the right move?
SRC: DarkReading
Wed, 16 Sep 2026 21:26:55 GMT
https://www.darkreading.com/cybersecurity-operations/ai-security-spending-jumps-fear-outpaces-proof-value
18
Anthropic wants Claude to analyze your bank account and financial data
Anthropic is testing a new personal finance feature called "Claude Money" that will allow you to connect your bank accounts directly to Claude and "understand your money." […]
SRC: BleepingComputer
Wed, 16 Sep 2026 20:35:48 -0400
https://www.bleepingcomputer.com/news/artificial-intelligence/anthropic-wants-claude-to-analyze-your-bank-account-and-financial-data/
Known Exploited — CISA KEV
| CVE | Product | Added to KEV |
|---|---|---|
| CVE-2026-58704 | Pixel (Google) | 2026-09-16 |
| CVE-2026-76460 | Identity Services Engine (Cisco) | 2026-09-16 |
| CVE-2026-87886 | Backup (Acronis) | 2026-09-16 |
| CVE-2026-76461 | Secure Email Gateway (Cisco) | 2026-09-14 |
| CVE-2026-84869 | ScreenConnect (ConnectWise) | 2026-09-11 |
| CVE-2026-42016 | Artifactory (JFrog) | 2026-09-11 |
| CVE-2026-42018 | Artifactory (JFrog) | 2026-09-11 |
| CVE-2026-85706 | Community Edition and Enterprise Edition (GitLab) | 2026-09-11 |
| CVE-2026-86060 | RouterOS (MikroTik) | 2026-09-10 |
| CVE-2026-67277 | RouterOS (MikroTik) | 2026-09-10 |
Indicators of Compromise (IOC)
Download Indicators of Compromise (IOC)
For SOC/NOC ingestion, threat intelligence platforms, and SIEM integration.
