CYBER THREAT INTEL
DAILY BRIEFING · 2026-09-22 12:15 UTC · REPORT BRIEF-20260922-121533
OPEN // LE
PERIOD: LAST 24 HOURS SOURCES: Ars Technica Security, BleepingComputer, Cyber Risk & Security, CyberScoop, DarkReading, Help Net Security
TOP 10 LATEST CYBERSECURITY STORIES from the last 24 hours.
10
Stories Featured
9
Sources
10
Active KEV CVEs
28
IOC Indicators
Top Stories
01
More Than a Third of Industrial Orgs See Cybersecurity Risk as a Top Obstacle to Growth, Study Finds
Industrial companies are increasing cybersecurity investment as connected operations, AI adoption, and IT/OT convergence expand operational risk.
medium
SRC: DarkReading
Tue, 22 Sep 2026 12:00:00 GMT
https://www.darkreading.com/cyber-risk/third-industrial-orgs-see-cybersecurity-risk-top-obstacle
02
The latest deepfake numbers give CISOs plenty to worry about
AI is letting cybercriminals reach deeper into organizations than a phishing email ever could. 41% of CISOs reported at least one social engineering incident involving a deepfake during an employee audio call in the past 12 months, according to Gartner. 36% reported the same for a video call. 79% of CISOs surveyed reported at least one phishing, spear-phishing, or business email compromise inciden
high
SRC: Help Net Security
Tue, 22 Sep 2026 12:05:36 +0000
https://www.helpnetsecurity.com/2026/09/22/cisos-deepfake-incidents-social-engineering-survey/
03
The next intellectual property thief may sound like your CEO
Impersonation, phishing and domain-name abuse are the most concerning types of online intellectual property infringement, according to CSC’s The State of Online IP Risk 2026 report. Internet and branded content, online marketplaces and paid search were the channels most frequently targeted. CSC surveyed 300 senior executives specializing in intellectual property law during the second quarter of 20
critical
SRC: Help Net Security
Tue, 22 Sep 2026 12:00:05 +0000
https://www.helpnetsecurity.com/2026/09/22/csc-online-intellectual-property-risk-report/
04
Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers
A Chinese threat actor has exploited the bug to exfiltrate sensitive information from nearly 1,000 ZyXEL switches. The post Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers appeared first on SecurityWeek.
critical
SRC: SecurityWeek
Tue, 22 Sep 2026 11:55:20 +0000
https://www.securityweek.com/recent-zyxel-switch-vulnerability-exploited-by-chinese-hackers/
05
DORA Year Two: Can Your SOC Actually See the Attack?
When the Digital Operational Resilience Act (DORA) became enforceable across the European Union in January 2025, it triggered an administrative sprint. Financial entities spent the first year establishing risk governance, assessing third-party service providers, updating contract clauses, and documenting incident escalation workflows. Now in its second year, the harder part of DORA is.
critical
SRC: The Hacker News
Tue, 22 Sep 2026 17:15:00 +0530
https://thehackernews.com/2026/09/dora-year-two-can-your-soc-actually-see.html
06
New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory
A new flaw in the Linux kernel's KVM virtualization code for ARM64 processors can leave a freed piece of host memory exposed to a guest virtual machine on hosts with nested virtualization enabled. The bug, tracked as CVE-2026-89775, allows a guest to read and write host kernel memory, and the researcher who found it says it can be used to escape the guest and run code on the host machine.
high
SRC: The Hacker News
Tue, 22 Sep 2026 17:08:40 +0530
https://thehackernews.com/2026/09/new-linux-kernel-flaw-gives-arm64-kvm.html
07
Malicious B-tree NPM Package Accumulates Millions of Downloads
Posing as the legitimate sorted-btree package, indexed-btree hides a malware trigger in its prototype method. The post Malicious B-tree NPM Package Accumulates Millions of Downloads appeared first on SecurityWeek.
high
SRC: SecurityWeek
Tue, 22 Sep 2026 11:33:59 +0000
https://www.securityweek.com/malicious-b-tree-npm-package-accumulates-millions-of-downloads/
08
Hackers Clone Legitimate Websites to Silently Trigger Chrome and Windows Zero-Day Exploits
Hackers are using convincing copies of trusted websites to turn an ordinary browser visit into a full Windows compromise. The campaign pairs targeted phishing emails with a chained set of previously unknown flaws in Google Chrome and Microsoft Windows, giving attackers a quiet path from a fake page to malware on a victim’s device. The […] The post Hackers Clone Legitimate Websites to Silently Trig
critical
SRC: Cyber Risk & Security
Tue, 22 Sep 2026 11:25:01 +0000
https://cybersecuritynews.com/hackers-clone-legitimate-websites/
09
SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE
A SharePoint Server vulnerability that Microsoft initially classified as a spoofing flaw with a CVSS score of 6.5 actually enables authenticated remote code execution, according to full technical details published today by Viettel Cyber Security researcher Dinh Ho Anh Khoa. The flaw, CVE-2026-65660, affects SharePoint Server 2016, 2019, and Subscription Edition. Patches have been.
critical
SRC: The Hacker News
Tue, 22 Sep 2026 16:47:41 +0530
https://thehackernews.com/2026/09/sharepoint-flaw-initially-listed-as.html
10
Aikido Security Unveils Altar-1 Open-Weight AI for Cybersecurity Defense
Aikido Security has unveiled Altar-1, an open-weight artificial intelligence model designed to run defensive cybersecurity workloads entirely inside an organization’s own infrastructure. The model aims to help security teams use advanced AI for vulnerability discovery and penetration testing without sending source code, internal documentation, or security findings to external cloud-based inference
critical
SRC: Cyber Risk & Security
Tue, 22 Sep 2026 10:50:04 +0000
https://cybersecuritynews.com/aikido-security-unveils-altar-1/
Known Exploited — CISA KEV
| CVE | Product | Added to KEV |
|---|---|---|
| CVE-2026-7273 | GS1900 Series Switches (Zyxel) | 2026-09-21 |
| CVE-2025-39964 | Kernel (Linux) | 2026-09-18 |
| CVE-2026-53266 | Kernel (Linux) | 2026-09-18 |
| CVE-2025-39682 | Kernel (Linux) | 2026-09-18 |
| CVE-2026-58704 | Pixel (Google) | 2026-09-16 |
| CVE-2026-76460 | Identity Services Engine (Cisco) | 2026-09-16 |
| CVE-2026-87886 | Backup (Acronis) | 2026-09-16 |
| CVE-2026-76461 | Secure Email Gateway (Cisco) | 2026-09-14 |
| CVE-2026-84869 | ScreenConnect (ConnectWise) | 2026-09-11 |
| CVE-2026-42016 | Artifactory (JFrog) | 2026-09-11 |
Indicators of Compromise (IOC)
Download Indicators of Compromise (IOC)
For SOC/NOC ingestion, threat intelligence platforms, and SIEM integration.
