CYBER THREAT INTEL
DAILY BRIEFING · 2026-09-24 12:15 UTC · REPORT BRIEF-20260924-121512
OPEN // LE
PERIOD: LAST 24 HOURS SOURCES: Ars Technica Security, BBC Technology, BleepingComputer, BleepingComputer (Google News), Cyber Risk & Security, Cyber Threat Intelligence
TOP 10 LATEST CYBERSECURITY STORIES from the last 24 hours.
19
Stories Featured
53
Sources
10
Active KEV CVEs
28
IOC Indicators
Top Stories
01
CISA: Ransomware gangs now exploiting critical TeamCity flaw
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies on Wednesday that ransomware gangs are now also exploiting a critical JetBrains TeamCity vulnerability patched in July. […]
SRC: BleepingComputer
Thu, 24 Sep 2026 06:42:37 -0400
https://www.bleepingcomputer.com/news/security/cisa-ransomware-gangs-now-exploiting-critical-teamcity-flaw/
02
SolarWinds Patches Critical RCE Flaws in Observability Self-Hosted
The vulnerabilities, tracked as CVE-2026-28324 and CVE-2026-28325, can be exploited without authentication.
The post SolarWinds Patches Critical RCE Flaws in Observability Self-Hosted appeared first on SecurityWeek.
SRC: SecurityWeek
Thu, 24 Sep 2026 10:40:40 +0000
https://www.securityweek.com/solarwinds-patches-critical-rce-flaws-in-observability-self-hosted/
03
OpenAI hacked Australian Medicare govt site, probed data providers
OpenAI agents targeted public data providers in multiple countries, probing some for vulnerabilities and exploiting a security weakness in an Australian government portal while performing information-retrieval tasks as part of a research project. […]
SRC: BleepingComputer
Thu, 24 Sep 2026 05:38:53 -0400
https://www.bleepingcomputer.com/news/security/openai-hacked-australian-medicare-govt-site-probed-data-providers/
04
17,000 URLs Reveal How ClickFix Turns Trusted Websites Into Malware Traps: Report by CTM360
ClickFix has become the most common way attackers get into enterprise networks, and it does it without an exploit, an attachment, or a file on disk. Our new global threat report traces the technique from a novelty in late 2023 to a subscription product with on-chain infrastructure and a state-sponso
SRC: The Hacker News
Thu, 24 Sep 2026 14:44:21 +0530
https://thehackernews.com/2026/09/17000-urls-reveal-how-clickfix-turns.html
05
US Court Sentences Armenian Man to Prison for Ryuk Ransomware Attacks
Karen Vardanyan has also been ordered to pay over $1.2 million in restitution to victims.
The post US Court Sentences Armenian Man to Prison for Ryuk Ransomware Attacks appeared first on SecurityWeek.
SRC: SecurityWeek
Thu, 24 Sep 2026 08:38:29 +0000
https://www.securityweek.com/us-court-sentences-armenian-man-to-prison-for-ryuk-ransomware-attacks/
06
What’s next for cybersecurity, according to Index Ventures’ Shardul Shah
As concern over AI safety and rogue agents continue to make headlines, it’s no surprise that cybersecurity stocks are rising, or that investors are pouring massive amounts of capital into startups trying to build the next generation of security for an AI-native world. We’re even seeing companies lik
SRC: TechCrunch Security
Wed, 23 Sep 2026 17:40:50 +0000
https://techcrunch.com/podcast/whats-next-for-cybersecurity-according-to-index-ventures-shardul-shah/
07
Ryuk ransomware operator sentenced to 2 years in prison
The Armenian national was extradited from Ukraine to the United States last year and pleaded guilty to cybercrimes in July.
The post Ryuk ransomware operator sentenced to 2 years in prison appeared first on CyberScoop.
SRC: CyberScoop
Wed, 23 Sep 2026 17:10:19 +0000
https://cyberscoop.com/ryuk-ransomware-operator-karen-vardanyan-sentenced/
08
OpenAI, Ukraine partner on ‘Daybreak’ program to protect power grids and water systems
A Ukrainian official said the government will use the tools to automate cybersecurity functions in critical infrastructure as the war with Russia continues.
The post OpenAI, Ukraine partner on ‘Daybreak’ program to protect power grids and water systems appeared first on CyberScoop.
SRC: CyberScoop
Wed, 23 Sep 2026 15:37:18 +0000
https://cyberscoop.com/openai-ukraine-cybersecurity-critical-infrastructure/
09
EDR Evasion Stack Helps Process Injection Slip Past Defenses
A process parameter-poisoning technique evades EDR by injecting code into process initialization structures without using the Windows APIs that EDR tools typically watch out for.
SRC: DarkReading
Wed, 23 Sep 2026 21:03:01 GMT
https://www.darkreading.com/endpoint-security/edr-evasion-stack-helps-process-injection-slip-past-defenses
10
How tax policy can stop threat actors from breaching US water systems
New federal programs take years to launch and fund. State and local governments need cybersecurity software now. The One Big Beautiful Bill already enables tax incentives. Congress should clarify and deploy them.
The post How tax policy can stop threat actors from breaching US water systems appeared
SRC: CyberScoop
Thu, 24 Sep 2026 10:00:00 +0000
https://cyberscoop.com/how-federal-tax-incentives-can-protect-state-local-cybersecurity-op-ed/
11
Astrana Health Data Breach Impacts Private, Confidential Information
Hackers impersonated the company’s personnel and contacted its employees to gain access to Astrana Health’s servers.
The post Astrana Health Data Breach Impacts Private, Confidential Information appeared first on SecurityWeek.
SRC: SecurityWeek
Thu, 24 Sep 2026 09:56:04 +0000
https://www.securityweek.com/astrana-health-data-breach-impacts-private-confidential-information/
12
A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You
The private email address GitLab gives you for filing issues by email is a credential. Anyone who gets it can email a patch that GitLab commits in your name, to any branch you can push to, including main, and can start CI/CD jobs that run as you.
GitLab shows each user this address behind a button
SRC: The Hacker News
Wed, 23 Sep 2026 22:23:10 +0530
https://thehackernews.com/2026/09/a-leaked-gitlab-issue-email-address.html
13
This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Move
A Windows malware called CLOSEDQUORUM is built to take orders from a vote of up to four AI models instead of an attacker's server, Cisco Talos said on September 22.
The models can choose to steal Windows credentials, saved browser passwords, and crypto wallet data. Talos has not seen this setup wor
SRC: The Hacker News
Wed, 23 Sep 2026 19:47:58 +0530
https://thehackernews.com/2026/09/windows-malware-is-built-to-let-up-to.html
14
GitLab Email Addresses Can Be Weaponized for Supply Chain Attacks
Incoming email addresses automatically assigned to each user on the platform contain highly privileged access tokens that attackers can use.
SRC: DarkReading
Wed, 23 Sep 2026 20:53:38 GMT
https://www.darkreading.com/application-security/gitlab-email-addresses-supply-chain-attacks
15
Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI
Unknown threat actors have managed to compromise two legitimate MemTensor packages across the npm and Python Package Index (PyPI) repositories to push a platform-specific Go-based implant dubbed sckit designed for Windows, Linux, and macOS.
According to reports from Aikido, SafeDep, Socket, and Ste
SRC: The Hacker News
Wed, 23 Sep 2026 19:22:46 +0530
https://thehackernews.com/2026/09/compromised-memtensor-packages-deliver.html
16
Island Raises $400 Million at $6.4 Billion Valuation
The enterprise security firm has raised more than $1 billion since its launch in 2020; Evolution Equity Partners led the latest funding round.
The post Island Raises $400 Million at $6.4 Billion Valuation appeared first on SecurityWeek.
SRC: SecurityWeek
Thu, 24 Sep 2026 11:39:09 +0000
https://www.securityweek.com/island-raises-400-million-at-6-4-billion-valuation/
17
OT Security Guidance: NIST Drafts Updated Guide, CISA/FBI Advise on ICS Integrators
Revision 4 of NIST’s operational technology security guide is open for public comments until November 30.
The post OT Security Guidance: NIST Drafts Updated Guide, CISA/FBI Advise on ICS Integrators appeared first on SecurityWeek.
SRC: SecurityWeek
Thu, 24 Sep 2026 11:05:16 +0000
https://www.securityweek.com/ot-security-guidance-nist-drafts-updated-guide-cisa-fbi-advise-on-ics-integrators/
18
Begin at the End: How to Enable Agentic Remediation
Agentic remediation is not an act of faith. We are talking about fixing known problems, not judgment calls about unfamiliar risk.
The post Begin at the End: How to Enable Agentic Remediation appeared first on SecurityWeek.
SRC: SecurityWeek
Thu, 24 Sep 2026 11:00:00 +0000
https://www.securityweek.com/begin-at-the-end-how-to-enable-agentic-remediation/
19
OpenAI Agent Bypassed an Australian Government Health Portal During Internal Research
OpenAI’s AI agent bypassed controls on an Australian health portal, accessed non-public files and triggered a government investigation. An OpenAI AI agent bypassed access controls on an Australian government health statistics portal in June, accessing both public and non-public files in what Austral
SRC: Security Affairs
Thu, 24 Sep 2026 10:31:52 +0000
https://securityaffairs.com/199662/ai/openai-agent-bypassed-an-australian-government-health-portal-during-internal-research.html
Known Exploited — CISA KEV
| CVE | Product | Added to KEV |
|---|---|---|
| CVE-2026-93952 | VeloCloud Orchestrator (Arista) | 2026-09-22 |
| CVE-2026-94127 | BIG-IP APM (F5) | 2026-09-22 |
| CVE-2026-93616 | Multiple Products (Check Point) | 2026-09-22 |
| CVE-2026-85102 | Multiple Products (Check Point) | 2026-09-22 |
| CVE-2026-7273 | GS1900 Series Switches (Zyxel) | 2026-09-21 |
| CVE-2025-39964 | Kernel (Linux) | 2026-09-18 |
| CVE-2026-53266 | Kernel (Linux) | 2026-09-18 |
| CVE-2025-39682 | Kernel (Linux) | 2026-09-18 |
| CVE-2026-58704 | Pixel (Google) | 2026-09-16 |
| CVE-2026-76460 | Identity Services Engine (Cisco) | 2026-09-16 |
Indicators of Compromise (IOC)
Download Indicators of Compromise (IOC)
For SOC/NOC ingestion, threat intelligence platforms, and SIEM integration.
