CYBER THREAT INTEL
DAILY BRIEFING · 2026-09-19 12:15 UTC · REPORT BRIEF-20260919-121514
OPEN // LE
PERIOD: LAST 24 HOURS SOURCES: Ars Technica Security, BBC Technology, BleepingComputer, BleepingComputer (Google News), Cyber Risk & Security, Cyber Threat Intelligence
TOP 10 LATEST CYBERSECURITY STORIES from the last 24 hours.
13
Stories Featured
53
Sources
10
Active KEV CVEs
28
IOC Indicators
Top Stories
01
SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE
SolarWinds has released security updates to address a high-severity flaw in Access Rights Manager (ARM) that, if successfully exploited, could lead to an unauthenticated remote code execution vulnerability.
The vulnerability, tracked as CVE-2026-28326, is rated 8.8 out of 10.0 on the CVSS scoring s
SRC: The Hacker News
Sat, 19 Sep 2026 15:01:17 +0530
https://thehackernews.com/2026/09/solarwinds-patches-arm-hard-coded-key.html
02
Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild
A critical vulnerability impacting Orkes Conductor is being actively exploited in the wild, according to Fortinet.
The vulnerability in question is CVE-2026-58138 (CVSS v3.1 score: 9.8/CVSS v4 score: 9.3), which relates to a case of unauthenticated remote code execution.
"Orkes Conductor 3.21.21 b
SRC: The Hacker News
Sat, 19 Sep 2026 13:48:54 +0530
https://thehackernews.com/2026/09/critical-pre-auth-rce-in-orkes.html
03
CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added three security flaws impacting the Linux kernel to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.
The vulnerabilities are listed below –
CVE-2025-39682 (CVSS score: 9.8)
SRC: The Hacker News
Sat, 19 Sep 2026 11:54:10 +0530
https://thehackernews.com/2026/09/cisa-flags-three-linux-kernel.html
04
Cisco Zero-Day Highlights API Endpoint Authentication Issues
The authentication bypass flaw CVE-2026-76460 impacts Cisco's Identity Services Engine (ISE) and received a maximum 10 out of 10 CVSS score.
SRC: DarkReading
Fri, 18 Sep 2026 19:26:47 GMT
https://www.darkreading.com/vulnerabilities-threats/cisco-zero-day-api-endpoint-authentication-issues
05
In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw
Noteworthy stories that might have slipped under the radar: Mandiant's 2026 AI risk report, PhantomRaven malware used by bug bounty hunter, WordPress plugin bug exploited.
The post In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw appeared first on SecurityWeek
SRC: SecurityWeek
Fri, 18 Sep 2026 14:25:00 +0000
https://www.securityweek.com/in-other-news-ransomware-developer-sentenced-plugin4shell-ai-attack-critical-sap-flaw/
06
Calling viral AI actress Tilly Norwood? Agree to a face scan first
AI actress Tilly Norwood went viral after glitching into Chinese on Piers Morgan Uncensored last night. Her "Talking Tilly" video call service face-scans every caller for an 18+ age check, senses callers' moods during calls, and shuts down permanently on September 27. We tried it and read the fine p
SRC: BleepingComputer
Sat, 19 Sep 2026 07:38:20 -0400
https://www.bleepingcomputer.com/news/security/calling-viral-ai-actress-tilly-norwood-agree-to-a-face-scan-first/
07
Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2
The Pakistan-aligned threat group tracked as Transparent Tribe (aka APT36 and Earth Karkaddan) has been attributed to a fresh set of cyber attacks targeting government and defense entities in India and Afghanistan.
The attacks, per Zscaler ThreatLabz, involve the use of previously undocumented tool
SRC: The Hacker News
Fri, 18 Sep 2026 20:54:16 +0530
https://thehackernews.com/2026/09/transparent-tribe-deploys-new-rust.html
08
CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories
An attacker copied about 170 of CrowdSec's private GitHub repositories on May 22 using the account of an employee who had just left, CrowdSec said on September 18.
The French security company had kept his GitHub access open. CrowdSec says his laptop was compromised in May's supply chain attack on T
SRC: The Hacker News
Sat, 19 Sep 2026 12:44:54 +0530
https://thehackernews.com/2026/09/crowdsec-says-tanstack-npm-attack-led.html
09
Gyazo Data Breach Exposes 23 Million User Records
A Gyazo breach exposed 23 million user records after attackers exploited a vulnerability in Helpfeel’s image upload server. Japanese software company Helpfeel is notifying Gyazo users about a data breach that compromised 23 million user records. Attackers gained unauthorized access by exploiting a v
SRC: Security Affairs
Fri, 18 Sep 2026 17:10:37 +0000
https://securityaffairs.com/199338/data-breach/gyazo-data-breach-exposes-23-million-user-records.html
10
Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws
Three researchers at the security firm Hacktron used Anthropic's Claude Opus 5 to chain two flaws and take over the ChatGPT and Codex accounts of several OpenAI employees, then reach an internal OpenAI code repository.
The chain began with a bug in the software that runs OpenAI's public help forum
SRC: The Hacker News
Sat, 19 Sep 2026 15:31:10 +0530
https://thehackernews.com/2026/09/claude-opus-5-helped-researchers-take.html
11
Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up
Google's Gemini model has become the latest artificial intelligence (AI) system to access the internet and break into other companies during a cybersecurity evaluation. The development was first reported by The Wall Street Journal.
The incidents occurred in May 2026 as part of a test run conducted
SRC: The Hacker News
Sat, 19 Sep 2026 13:21:34 +0530
https://thehackernews.com/2026/09/google-gemini-broke-into-real-company.html
12
Vectra AI Launches Ascent to Help Address New Era of AI-Driven Attacks
The new program expands Vectra AI's partner strategy as increasingly complex security environments and the growing use of AI create demand for broader AI expertise, services, and security outcomes.
SRC: DarkReading
Fri, 18 Sep 2026 20:24:51 GMT
https://www.darkreading.com/cyberattacks-data-breaches/vectra-ai-launches-ascent-new-era-ai-driven-attacks
13
EY Survey Finds Autonomous AI Implementation Outpaces Oversight
A new survey of senior AI execs shows that while organizations are rapidly deploying AI and autonomous systems, their process and controls are not keeping pace.
SRC: DarkReading
Fri, 18 Sep 2026 19:23:48 GMT
https://www.darkreading.com/cyberattacks-data-breaches/ey-survey-autonomous-ai-implementation-outpaces-oversight
Known Exploited — CISA KEV
| CVE | Product | Added to KEV |
|---|---|---|
| CVE-2025-39964 | Kernel (Linux) | 2026-09-18 |
| CVE-2026-53266 | Kernel (Linux) | 2026-09-18 |
| CVE-2025-39682 | Kernel (Linux) | 2026-09-18 |
| CVE-2026-58704 | Pixel (Google) | 2026-09-16 |
| CVE-2026-76460 | Identity Services Engine (Cisco) | 2026-09-16 |
| CVE-2026-87886 | Backup (Acronis) | 2026-09-16 |
| CVE-2026-76461 | Secure Email Gateway (Cisco) | 2026-09-14 |
| CVE-2026-84869 | ScreenConnect (ConnectWise) | 2026-09-11 |
| CVE-2026-42016 | Artifactory (JFrog) | 2026-09-11 |
| CVE-2026-42018 | Artifactory (JFrog) | 2026-09-11 |
Indicators of Compromise (IOC)
Download Indicators of Compromise (IOC)
For SOC/NOC ingestion, threat intelligence platforms, and SIEM integration.
