CYBER THREAT INTEL
DAILY BRIEFING · 2026-09-28 12:15 UTC · REPORT BRIEF-20260928-121546
OPEN // LE
PERIOD: LAST 24 HOURS SOURCES: Ars Technica Security, BBC Technology, BleepingComputer, BleepingComputer (Google News), Cyber Risk & Security, Cyber Threat Intelligence
TOP 10 LATEST CYBERSECURITY STORIES from the last 24 hours.
13
Stories Featured
53
Sources
10
Active KEV CVEs
28
IOC Indicators
Top Stories
01
Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign
The extortion group has modified its exploit in new attacks targeting the PeopleSoft vulnerability CVE-2026-35273.
The post Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign appeared first on SecurityWeek.
SRC: SecurityWeek
Mon, 28 Sep 2026 10:56:46 +0000
https://www.securityweek.com/google-warns-of-shinyhunters-fresh-oracle-peoplesoft-campaign/
02
Nvidia Unveils AI Agent Safety Platform With Hardware-Based Watchdog
The platform combines open source software and a reference system design to keep AI agents within set boundaries.
The post Nvidia Unveils AI Agent Safety Platform With Hardware-Based Watchdog appeared first on SecurityWeek.
SRC: SecurityWeek
Mon, 28 Sep 2026 10:27:01 +0000
https://www.securityweek.com/nvidia-unveils-ai-agent-safety-platform-with-hardware-based-watchdog/
03
JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources
The threat actor known as JADEPUFFER has been observed orchestrating destructive actions within a Microsoft Azure environment using compromised service principals.
Microsoft, which is tracking the activity under the name Storm-3168, has called it an evolution of the threat actor's tradecraft. The a
SRC: The Hacker News
Mon, 28 Sep 2026 14:38:21 +0530
https://thehackernews.com/2026/09/jadepuffer-linked-attackers-used.html
04
U.S. CISA adds Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026
SRC: Security Affairs
Mon, 28 Sep 2026 08:55:22 +0000
https://securityaffairs.com/199891/hacking/u-s-cisa-adds-citrix-netscaler-flaws-to-its-known-exploited-vulnerabilities-catalog.html
05
Storm-3168, Linked to JADEPUFFER, Abused Stolen Azure Identities
Microsoft details Storm-3168, the JADEPUFFER-linked actor that used stolen service principals to delete Azure storage in minutes and harvest keys. Microsoft just published the first detailed look at what JADEPUFFER does inside Azure. Sysdig first spotted the group’s activity in July 2026 and called
SRC: Security Affairs
Mon, 28 Sep 2026 10:46:05 +0000
https://securityaffairs.com/199905/cyber-crime/storm-3168-linked-to-jadepuffer-abused-stolen-azure-identities.html
06
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 116
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Threat Intel | One Kit, Forty Companies: How a Malware-as-a-Service Platform Used GitHub as a Distribution Network for its Campaign Group Policy
SRC: Security Affairs
Sun, 27 Sep 2026 15:05:39 +0000
https://securityaffairs.com/199850/malware/security-affairs-malware-newsletter-round-116.html
07
Security Affairs newsletter Round 597 by Pierluigi Paganini – INTERNATIONAL EDITION
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. OpenAI Agents Accessed US Government Websites Without
SRC: Security Affairs
Sun, 27 Sep 2026 13:40:23 +0000
https://securityaffairs.com/199841/breaking-news/security-affairs-newsletter-round-597-by-pierluigi-paganini-international-edition.html
08
DC Health Agency Exposes 400,000 Beneficiary Records
The Medicaid IDs and other information of Medicaid and DC Healthcare Alliance beneficiaries were exposed.
The post DC Health Agency Exposes 400,000 Beneficiary Records appeared first on SecurityWeek.
SRC: SecurityWeek
Mon, 28 Sep 2026 11:29:29 +0000
https://www.securityweek.com/dc-health-agency-exposes-400000-beneficiary-records/
09
Bitget resumes Bitcoin withdrawals after $387.5 million crypto heist
Cryptocurrency exchange Bitget has resumed Bitcoin withdrawals suspended after suspected North Korean hackers breached its systems last week and stole over $350 million. […]
SRC: BleepingComputer
Mon, 28 Sep 2026 05:25:29 -0400
https://www.bleepingcomputer.com/news/security/bitget-resumes-bitcoin-withdrawals-after-3875-million-crypto-heist/
10
New Mexico Jury Finds Facebook Liable for Deceiving Users About Privacy Protections
A New Mexico jury has found Facebook liable for deceiving users about privacy protections on the platform.
The post New Mexico Jury Finds Facebook Liable for Deceiving Users About Privacy Protections appeared first on SecurityWeek.
SRC: SecurityWeek
Mon, 28 Sep 2026 10:40:01 +0000
https://www.securityweek.com/new-mexico-jury-finds-facebook-liable-for-deceiving-users-about-privacy-protections/
11
Kiteworks Urges Server Shutdown, Finds Advanced Forms Vulnerability
The company says the measure was precautionary and that it has no evidence of Kiteworks or customer systems being compromised.
The post Kiteworks Urges Server Shutdown, Finds Advanced Forms Vulnerability appeared first on SecurityWeek.
SRC: SecurityWeek
Mon, 28 Sep 2026 09:44:27 +0000
https://www.securityweek.com/kiteworks-urges-server-shutdown-finds-advanced-forms-vulnerability/
12
US soldier gets 70 months in prison for extorting 10 tech, telecom firms
A former U.S. Army soldier has been sentenced to 70 months in prison for hacking and extorting at least 10 U.S. technology and telecommunications companies between April 2023 and December 2024. […]
SRC: BleepingComputer
Mon, 28 Sep 2026 03:30:15 -0400
https://www.bleepingcomputer.com/news/security/us-soldier-gets-70-months-in-prison-for-extorting-10-tech-telecom-firms/
13
OpenAI is preparing “o,” an always-on ChatGPT assistant that could handle email
OpenAI is testing a new always-on assistant called "o", and references to the unannounced feature briefly showed up on the company's website. […]
SRC: BleepingComputer
Sun, 27 Sep 2026 19:40:39 -0400
https://www.bleepingcomputer.com/news/artificial-intelligence/openai-is-preparing-o-an-always-on-chatgpt-assistant-that-could-handle-email/
Known Exploited — CISA KEV
| CVE | Product | Added to KEV |
|---|---|---|
| CVE-2026-88772 | NetScaler (Citrix) | 2026-09-27 |
| CVE-2026-88771 | NetScaler (Citrix) | 2026-09-27 |
| CVE-2026-67279 | RouterOS (MikroTik) | 2026-09-25 |
| CVE-2026-65660 | SharePoint (Microsoft) | 2026-09-25 |
| CVE-2026-87902 | Core (WordPress) | 2026-09-25 |
| CVE-2026-5430 | Multiple Products (WSO2) | 2026-09-24 |
| CVE-2026-71362 | Commerce and Magento (Adobe) | 2026-09-24 |
| CVE-2026-93952 | VeloCloud Orchestrator (Arista) | 2026-09-22 |
| CVE-2026-94127 | BIG-IP APM (F5) | 2026-09-22 |
| CVE-2026-93616 | Multiple Products (Check Point) | 2026-09-22 |
Indicators of Compromise (IOC)
Download Indicators of Compromise (IOC)
For SOC/NOC ingestion, threat intelligence platforms, and SIEM integration.
