CYBER THREAT INTEL
DAILY BRIEFING · 2026-09-21 12:16 UTC · REPORT BRIEF-20260921-121601
OPEN // LE
PERIOD: LAST 24 HOURS SOURCES: Ars Technica Security, BBC Technology, BleepingComputer, BleepingComputer (Google News), Cyber Risk & Security, Cyber Threat Intelligence
TOP 10 LATEST CYBERSECURITY STORIES from the last 24 hours.
15
Stories Featured
53
Sources
10
Active KEV CVEs
28
IOC Indicators
Top Stories
01
Organizations Warned of 3 Exploited Linux Kernel Vulnerabilities
Attackers could exploit the flaws to cause denial-of-service conditions, disclose memory, or modify memory.
The post Organizations Warned of 3 Exploited Linux Kernel Vulnerabilities appeared first on SecurityWeek.
SRC: SecurityWeek
Mon, 21 Sep 2026 09:31:12 +0000
https://www.securityweek.com/organizations-warned-of-3-exploited-linux-kernel-vulnerabilities/
02
ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure
Threat actors are leveraging ClickFix-like lures to deliver a previously undocumented remote access trojan (RAT) called ChainScript.
"ChainScript has appeared under multiple build names, including ComponentTask33, UpdateDigital, HostShared, and OrchidViolet66, while presenting itself as Spotify, Zo
SRC: The Hacker News
Mon, 21 Sep 2026 14:09:38 +0530
https://thehackernews.com/2026/09/clickfix-lures-deploy-chainscript-rat.html
03
U.S. CISA adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added [1, 2] the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: Below
SRC: Security Affairs
Sun, 20 Sep 2026 16:12:59 +0000
https://securityaffairs.com/199430/security/u-s-cisa-adds-linux-kernel-flaws-to-its-known-exploited-vulnerabilities-catalog-2.html
04
Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors
The North Korean threat actor known as Jade Sleet has been attributed to the compromise of an India-based "much smaller organization" in the information technology (IT) services industry, once again highlighting how the adversary continues to target developers to breach target networks.
Cybersecuri
SRC: The Hacker News
Mon, 21 Sep 2026 11:36:44 +0530
https://thehackernews.com/2026/09/jade-sleet-linked-to-indian-it-provider.html
05
Rust Team Members and Popular Crate Owners Targeted via Video Calls
It’s unclear if the attacks are part of previous campaigns against Rust, but the techniques used by the attackers match those used by North Korea.
The post Rust Team Members and Popular Crate Owners Targeted via Video Calls appeared first on SecurityWeek.
SRC: SecurityWeek
Mon, 21 Sep 2026 11:57:35 +0000
https://www.securityweek.com/rust-team-members-and-popular-crate-owners-targeted-via-video-calls/
06
AI Hallucinations Nearly Triggered a US-China Military Confrontation
An AI-generated intelligence report falsely identified weapons on a Chinese ship, nearly triggering a US military operation during the Iran war. According to CNN, four sources familiar with the episode say an intelligence report circulated through the military claiming a Chinese vessel in the Middle
SRC: Security Affairs
Sun, 20 Sep 2026 13:44:39 +0000
https://securityaffairs.com/199415/ai/ai-hallucination-nearly-triggered-a-us-china-military-confrontation.html
07
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 115
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Gray Rabbits and the Tale of a One-Click Backdoor Red Heron exploits Gitea n-day flaw in multinational campaign, exposing new Linux rootkit Malic
SRC: Security Affairs
Sun, 20 Sep 2026 12:22:06 +0000
https://securityaffairs.com/199409/malware/security-affairs-malware-newsletter-round-115.html
08
CrowdSec Confirms Source Code Stolen in Supply Chain Attack
The cybersecurity firm believes the data breach was the result of the May 2026 TanStack supply chain attack.
The post CrowdSec Confirms Source Code Stolen in Supply Chain Attack appeared first on SecurityWeek.
SRC: SecurityWeek
Mon, 21 Sep 2026 10:55:46 +0000
https://www.securityweek.com/crowdsec-confirms-source-code-stolen-in-supply-chain-attack/
09
The Target Is No Longer the Model. It’s the Agent.
AI agents are becoming the new attack surface, exposed to poisoned skills, prompt injection, jailbreaks and attacks through connected tools. I read the AI security research published in a single month, February 2026, and when you put it all together, it’s not a list of curiosities. It’s a field guid
SRC: Security Affairs
Mon, 21 Sep 2026 08:27:47 +0000
https://securityaffairs.com/199454/ai/the-target-is-no-longer-the-model-its-the-agent.html
10
Google Confirms Gemini AI Breached Three Firms
Google is the latest AI giant to confirm that its models escaped a testing environment and hacked real companies.
The post Google Confirms Gemini AI Breached Three Firms appeared first on SecurityWeek.
SRC: SecurityWeek
Mon, 21 Sep 2026 07:20:46 +0000
https://www.securityweek.com/google-confirms-gemini-ai-breached-three-firms/
11
Malicious npm packages evade install-script defenses at runtime
An ongoing npm malware campaign involving the 'indexed-btree' package shows how threat actors bypass supply chain defenses by hiding malicious code in a package's normal runtime behavior rather than in installation scripts. […]
SRC: BleepingComputer
Sun, 20 Sep 2026 10:11:21 -0400
https://www.bleepingcomputer.com/news/security/malicious-npm-packages-evade-install-script-defenses-at-runtime/
12
Microsoft: September updates break File History backup feature
Microsoft warned that the built-in File History backup feature in Windows may stop working on some systems after installing the September 2026 security updates. […]
SRC: BleepingComputer
Mon, 21 Sep 2026 07:45:54 -0400
https://www.bleepingcomputer.com/news/microsoft/microsoft-september-updates-break-file-history-backup-feature/
13
A BYD Shark 6 Hack Shows the Risks of Connected Cars
A BYD Shark 6 was remotely hacked, exposing vehicle controls, location tracking and cabin audio, raising serious connected-car security concerns. A journalist drove a BYD Shark 6 down a country road outside Canberra while a hacker sitting on the shoulder killed the headlights with a keystroke. That’
SRC: Security Affairs
Mon, 21 Sep 2026 10:32:03 +0000
https://securityaffairs.com/199460/hacking/a-byd-shark-6-hack-shows-the-risks-of-connected-cars.html
14
Colorado Water Utilities Hit by Cyberattacks Targeting OT Systems
The hackers changed equipment settings, disabled remote access and alarms, and altered pumping cycles, officials said.
The post Colorado Water Utilities Hit by Cyberattacks Targeting OT Systems appeared first on SecurityWeek.
SRC: SecurityWeek
Mon, 21 Sep 2026 10:03:44 +0000
https://www.securityweek.com/colorado-water-utilities-hit-by-cyberattacks-targeting-ot-systems/
15
UK Police Data Faces Long-Standing Microsoft Cloud Security Concerns
A 2017 UK assessment warned that police data on Microsoft Azure could face foreign access risks. The risks may still exist. A Guardian investigation has surfaced a 2017 document signed off by then City of London police commissioner Ian Dyson, who also held the title of senior information risk owner
SRC: Security Affairs
Mon, 21 Sep 2026 07:28:40 +0000
https://securityaffairs.com/199442/uncategorized/uk-police-data-faces-long-standing-microsoft-cloud-security-concerns.html
Known Exploited — CISA KEV
| CVE | Product | Added to KEV |
|---|---|---|
| CVE-2025-39964 | Kernel (Linux) | 2026-09-18 |
| CVE-2026-53266 | Kernel (Linux) | 2026-09-18 |
| CVE-2025-39682 | Kernel (Linux) | 2026-09-18 |
| CVE-2026-58704 | Pixel (Google) | 2026-09-16 |
| CVE-2026-76460 | Identity Services Engine (Cisco) | 2026-09-16 |
| CVE-2026-87886 | Backup (Acronis) | 2026-09-16 |
| CVE-2026-76461 | Secure Email Gateway (Cisco) | 2026-09-14 |
| CVE-2026-84869 | ScreenConnect (ConnectWise) | 2026-09-11 |
| CVE-2026-42016 | Artifactory (JFrog) | 2026-09-11 |
| CVE-2026-42018 | Artifactory (JFrog) | 2026-09-11 |
Indicators of Compromise (IOC)
Download Indicators of Compromise (IOC)
For SOC/NOC ingestion, threat intelligence platforms, and SIEM integration.
