CYBER THREAT INTEL
DAILY BRIEFING · 2026-09-27 12:15 UTC · REPORT BRIEF-20260927-121523
OPEN // LE
PERIOD: LAST 24 HOURS SOURCES: Ars Technica Security, BBC Technology, BleepingComputer, BleepingComputer (Google News), Cyber Risk & Security, Cyber Threat Intelligence
TOP 10 LATEST CYBERSECURITY STORIES from the last 24 hours.
12
Stories Featured
53
Sources
10
Active KEV CVEs
28
IOC Indicators
Top Stories
01
Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks
CISA added CVE-2026-65660 to its KEV catalog, giving federal agencies a patching deadline of September 28.
The post Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks appeared first on SecurityWeek.
SRC: SecurityWeek
Sun, 27 Sep 2026 09:23:09 +0000
https://www.securityweek.com/microsoft-sharepoint-flaw-cve-2026-65660-now-exploited-in-attacks/
02
Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation
Two new unpatched zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances that allow remote code execution are being actively exploited in the wild, security firm watchTowr said on September 26.
Citrix has not confirmed the flaws or published a fix. Some administrators say
SRC: The Hacker News
Sun, 27 Sep 2026 13:17:57 +0530
https://thehackernews.com/2026/09/warning-two-unpatched-citrix-netscaler.html
03
ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks
The ShinyHunters extortion gang is using a URL-encoding trick to bypass web application firewall rules that mitigate the Oracle PeopleSoft CVE-2026-35273 flaw, allowing the threat actors to resume widespread exploitation of a flaw on vulnerable servers. […]
SRC: BleepingComputer
Sat, 26 Sep 2026 15:03:34 -0400
https://www.bleepingcomputer.com/news/security/shinyhunters-uses-waf-bypass-trick-in-oracle-peoplesoft-attacks/
04
Exploit.in Database Reveals the Roots of Today’s Ransomware Ecosystem
Exploit.in data shows how a 2005 cybercrime forum helped shape today’s ransomware ecosystem, with users and practices surviving for decades. Ransomnews researcher Dancho Danchev dug up a database dump of Exploit.in covering its first three years, from February 2005 to May 2008, and the numbers insid
SRC: Security Affairs
Sat, 26 Sep 2026 14:34:26 +0000
https://securityaffairs.com/199800/cyber-crime/exploit-in-database-reveals-the-roots-of-todays-ransomware-ecosystem.html
05
China and US Agree to Establish AI Safety Channel and Continue Trade and Military Talks
The US and China agreed to set up a communication mechanism for artificial intelligence-related incidents.
The post China and US Agree to Establish AI Safety Channel and Continue Trade and Military Talks appeared first on SecurityWeek.
SRC: SecurityWeek
Sat, 26 Sep 2026 18:09:28 +0000
https://www.securityweek.com/china-and-us-agree-to-establish-ai-safety-channel-and-continue-trade-and-military-talks/
06
Rydox Admin Faces 20 Years After Selling Stolen Data and Fraud Tools
Kosovo national Ardit Kutleshi pleaded guilty to running Rydox, a cybercrime marketplace that sold stolen identities and credentials for years. Ardit Kutleshi, 28 years old and a citizen of Kosovo, pleaded guilty last week to building and running the cybercrime marketplace Rydox. The Rydox marketpla
SRC: Security Affairs
Sun, 27 Sep 2026 09:27:52 +0000
https://securityaffairs.com/199825/uncategorized/rydox-admin-faces-20-years-after-selling-stolen-data-and-fraud-tools.html
07
Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials
The Psychedelic Stealer malware distributed via compromised Ukrainian websites using ClickFix-style Cloudflare verification checks is part of a wider malware-as-a-service (MaaS) platform called Lunex.
The new findings come from Ontinue, which described the activity as a four-stage attack chain aime
SRC: The Hacker News
Sat, 26 Sep 2026 23:52:52 +0530
https://thehackernews.com/2026/09/lunex-stealer-abuses-amd-driver-to.html
08
GitHub Actions re-enabled with Mini Shai-Hulud payload still active
Two third-party GitHub Actions previously compromised in a Mini Shai-Hulud campaign were re-enabled by their maintainer and remained accessible for more than a week despite still pointing to malicious code. […]
SRC: BleepingComputer
Sat, 26 Sep 2026 10:19:46 -0400
https://www.bleepingcomputer.com/news/security/github-actions-re-enabled-with-mini-shai-hulud-payload-still-active/
09
OpenAI's AI agents accidentally uploaded user-provided images to third-party sites
OpenAI says its AI agents uploaded user-provided images to third-party image-hosting services while carrying out research and evaluation tasks. […]
SRC: BleepingComputer
Sat, 26 Sep 2026 08:28:41 -0400
https://www.bleepingcomputer.com/news/artificial-intelligence/openais-ai-agents-accidentally-uploaded-user-provided-images-to-third-party-sites/
10
Claude Opus 5.5 uses 95% fewer em dashes, but its answers are getting longer
Anthropic's Claude Opus 5.5 appears to be changing how it writes, with new analysis showing fewer obvious AI writing patterns, shorter sentences, and simpler wording compared with Opus 5. […]
SRC: BleepingComputer
Sat, 26 Sep 2026 12:26:58 -0400
https://www.bleepingcomputer.com/news/artificial-intelligence/claude-opus-55-uses-95-percent-fewer-em-dashes-but-its-answers-are-getting-longer/
11
Microsoft pauses KB5002907 update after Office license deactivations
Microsoft has paused the rollout of the KB5002907 Microsoft 365 update after users report that it deactivated, or in some cases completely removed, perpetual Office 2016 and Office 2019 installations. […]
SRC: BleepingComputer
Sat, 26 Sep 2026 11:50:38 -0400
https://www.bleepingcomputer.com/news/microsoft/microsoft-365-kb5002907-update-paused-after-office-license-deactivations/
12
OpenAI Agents Accessed US Government Websites Without Authorization
OpenAI is investigating AI agents that accessed US gov websites without authorization, including an attempted Education Department hack. OpenAI disclosed on Friday that its AI agents had interacted with US government websites in ways nobody planned or authorized, as part of what the company is calli
SRC: Security Affairs
Sat, 26 Sep 2026 15:41:32 +0000
https://securityaffairs.com/199815/ai/openai-agents-accessed-us-government-websites-without-authorization.html
Known Exploited — CISA KEV
| CVE | Product | Added to KEV |
|---|---|---|
| CVE-2026-67279 | RouterOS (MikroTik) | 2026-09-25 |
| CVE-2026-65660 | SharePoint (Microsoft) | 2026-09-25 |
| CVE-2026-87902 | Core (WordPress) | 2026-09-25 |
| CVE-2026-5430 | Multiple Products (WSO2) | 2026-09-24 |
| CVE-2026-71362 | Commerce and Magento (Adobe) | 2026-09-24 |
| CVE-2026-93952 | VeloCloud Orchestrator (Arista) | 2026-09-22 |
| CVE-2026-94127 | BIG-IP APM (F5) | 2026-09-22 |
| CVE-2026-93616 | Multiple Products (Check Point) | 2026-09-22 |
| CVE-2026-85102 | Multiple Products (Check Point) | 2026-09-22 |
| CVE-2026-7273 | GS1900 Series Switches (Zyxel) | 2026-09-21 |
Indicators of Compromise (IOC)
Download Indicators of Compromise (IOC)
For SOC/NOC ingestion, threat intelligence platforms, and SIEM integration.
