CYBER THREAT INTEL
DAILY BRIEFING · 2026-09-20 12:15 UTC · REPORT BRIEF-20260920-121538
OPEN // LE
PERIOD: LAST 24 HOURS SOURCES: Ars Technica Security, BBC Technology, BleepingComputer, BleepingComputer (Google News), Cyber Risk & Security, Cyber Threat Intelligence
TOP 10 LATEST CYBERSECURITY STORIES from the last 24 hours.
11
Stories Featured
53
Sources
10
Active KEV CVEs
28
IOC Indicators
Top Stories
01
TigerByte Cyber Emerges From Stealth With $3 Million in Funding
The company has secured over $7 million in contracts with US government agencies, including the US Space Force, the US Navy, and DARPA.
The post TigerByte Cyber Emerges From Stealth With $3 Million in Funding appeared first on SecurityWeek.
SRC: SecurityWeek
Sat, 19 Sep 2026 14:30:00 +0000
https://www.securityweek.com/tigerbyte-cyber-emerges-from-stealth-with-3-million-in-funding/
02
Can You Prove a New CVE Is Exploitable Before Attackers Do? Learn How in This Webinar
A new CVE drops. Your scanner finds it. The severity score looks ugly.
But that still does not answer the question that matters: Can it actually be exploited in your environment?
Mythos-class AI is compressing the time between disclosure and working exploitation, while many security programs still
SRC: The Hacker News
Sat, 19 Sep 2026 18:58:48 +0530
https://thehackernews.com/2026/09/can-you-prove-new-cve-is-exploitable.html
03
AI Helps Hackers Hijack OpenAI Staff Accounts Through a Forum
AI helped researchers exploit a Discourse flaw in under 72 hours, hijacking OpenAI staff accounts and exposing the risks of shared SSO. Three researchers at Hacktron just took over ChatGPT and Codex accounts belonging to OpenAI staff. The attack did not rely on phishing techniques or a leaked passwo
SRC: Security Affairs
Sat, 19 Sep 2026 13:01:08 +0000
https://securityaffairs.com/199378/ai/ai-helps-hackers-hijack-openai-staff-accounts-through-a-forum.html
04
ShinyHunters hacks Clop leak site, threatens to extort ransomware gang
The ShinyHunters extortion gang breached the Clop (aka Cl0p) ransomware operation's data leak site, defacing the Tor site and allegedly stealing server data and the private keys for its onion service. […]
SRC: BleepingComputer
Sat, 19 Sep 2026 09:48:32 -0400
https://www.bleepingcomputer.com/news/security/shinyhunters-hacks-clop-leak-site-threatens-to-extort-ransomware-gang/
05
North Korean WaterPlum hackers infected 30,000 devices worldwide
A joint law enforcement advisory warns that the North Korean hacking group WaterPlum compromised at least 30,000 devices worldwide from December 2025 through July 2026 and transferred more than $10.7 million in stolen cryptocurrency to North Korea. […]
SRC: BleepingComputer
Sat, 19 Sep 2026 10:05:15 -0400
https://www.bleepingcomputer.com/news/security/north-korean-waterplum-hackers-infected-30-000-devices-worldwide/
06
Google Gemini also Broke Out of Its Test Environment
Google Gemini escaped a cyber test environment, reached three real companies, and exposed why AI security tests need strict isolation. Google has confirmed that one of its Gemini models broke into the systems of three real companies during a cybersecurity test in May. The incident is the first publi
SRC: Security Affairs
Sat, 19 Sep 2026 14:09:34 +0000
https://securityaffairs.com/199392/ai/google-gemini-also-broke-out-of-its-test-environment.html
07
Identity Visibility in 2026: The Foundation of Identity Security
Identity visibility is a starting point for modern identity security, because stolen and misused credentials are among the most frequently reported initial access vectors in breach research, including Verizon's annual Data Breach Investigations Report. This article explains what identity visibility
SRC: The Hacker News
Sat, 19 Sep 2026 18:58:41 +0530
https://thehackernews.com/2026/09/identity-visibility-in-2026-foundation.html
08
Security Affairs newsletter Round 595 by Pierluigi Paganini – INTERNATIONAL EDITION
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. Google Gemini also Broke Out of Its Test Environment
SRC: Security Affairs
Sun, 20 Sep 2026 00:08:59 +0000
https://securityaffairs.com/199400/security/security-affairs-newsletter-round-595-by-pierluigi-paganini-international-edition.html
09
Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws
Three researchers at the security firm Hacktron used Anthropic's Claude Opus 5 to chain two flaws and take over the ChatGPT and Codex accounts of several OpenAI employees, then reach an internal OpenAI code repository.
The chain began with a bug in the software that runs OpenAI's public help forum
SRC: The Hacker News
Sun, 20 Sep 2026 00:06:53 +0530
https://thehackernews.com/2026/09/claude-opus-5-helped-researchers-take.html
10
Google’s Gemini is the latest AI model to hack other companies
Google said Gemini had "acted appropriately" by ending each hack immediately.
SRC: TechCrunch Security
Sat, 19 Sep 2026 17:30:00 +0000
https://techcrunch.com/2026/09/19/googles-gemini-is-the-latest-ai-model-to-hack-other-companies/
11
BragJack attacks hijack AI browser agents through malicious extensions
BragJack, a proof-of-concept attack from Forever Security's Gal Weizman, hijacks the AI assistants in Chrome, Edge, Opera Neon, Perplexity Comet, and Claude in Chrome using one malicious extension. The Prompt Forcing technique earned over $20,000 in bounties and two CVEs. […]
SRC: BleepingComputer
Sat, 19 Sep 2026 10:56:31 -0400
https://www.bleepingcomputer.com/news/security/bragjack-attacks-hijack-ai-browser-agents-through-malicious-extensions/
Known Exploited — CISA KEV
| CVE | Product | Added to KEV |
|---|---|---|
| CVE-2025-39964 | Kernel (Linux) | 2026-09-18 |
| CVE-2026-53266 | Kernel (Linux) | 2026-09-18 |
| CVE-2025-39682 | Kernel (Linux) | 2026-09-18 |
| CVE-2026-58704 | Pixel (Google) | 2026-09-16 |
| CVE-2026-76460 | Identity Services Engine (Cisco) | 2026-09-16 |
| CVE-2026-87886 | Backup (Acronis) | 2026-09-16 |
| CVE-2026-76461 | Secure Email Gateway (Cisco) | 2026-09-14 |
| CVE-2026-84869 | ScreenConnect (ConnectWise) | 2026-09-11 |
| CVE-2026-42016 | Artifactory (JFrog) | 2026-09-11 |
| CVE-2026-42018 | Artifactory (JFrog) | 2026-09-11 |
Indicators of Compromise (IOC)
Download Indicators of Compromise (IOC)
For SOC/NOC ingestion, threat intelligence platforms, and SIEM integration.
