CYBER THREAT INTEL
DAILY BRIEFING · 2026-09-29 12:15 UTC · REPORT BRIEF-20260929-121511
OPEN // LE
PERIOD: LAST 24 HOURS SOURCES: Ars Technica Security, BBC Technology, BleepingComputer, BleepingComputer (Google News), Cyber Risk & Security, Cyber Threat Intelligence
TOP 10 LATEST CYBERSECURITY STORIES from the last 24 hours.
21
Stories Featured
53
Sources
10
Active KEV CVEs
28
IOC Indicators
Top Stories
01
Vietnamese man charged in $16 million 'pig butchering' crypto scam
A Vietnamese national was charged with money laundering for his role in a massive "pig butchering" scam, which defrauded a victim out of $16 million worth of cryptocurrency. […]
SRC: BleepingComputer
Tue, 29 Sep 2026 07:41:53 -0400
https://www.bleepingcomputer.com/news/security/vietnamese-man-charged-in-16-million-pig-butchering-crypto-scam/
02
Kiteworks patches critical flaw, brings customer systems online
American tech company Kiteworks has lifted a precautionary advisory asking customers to shut down systems after patching a critical vulnerability. […]
SRC: BleepingComputer
Tue, 29 Sep 2026 05:04:06 -0400
https://www.bleepingcomputer.com/news/security/kiteworks-lifts-shutdown-warning-after-patching-critical-flaw/
03
Apple patches CoreGraphics zero-day flaw exploited in attacks
Apple released security updates to fix a zero-day vulnerability exploited in "extremely sophisticated" targeted attacks on iOS devices. […]
SRC: BleepingComputer
Tue, 29 Sep 2026 03:33:12 -0400
https://www.bleepingcomputer.com/news/security/apple-patches-coregraphics-zero-day-flaw-exploited-in-attacks/
04
Apple Patches Zero-Day Linked to ‘Extremely Sophisticated Attack’
Apple released iOS and macOS updates to patch a zero-day vulnerability (CVE-2026-86950) reported by Meta’s product security team.
The post Apple Patches Zero-Day Linked to ‘Extremely Sophisticated Attack’ appeared first on SecurityWeek.
SRC: SecurityWeek
Tue, 29 Sep 2026 06:18:27 +0000
https://www.securityweek.com/apple-patches-meta-reported-zero-day-linked-to-extremely-sophisticated-attack/
05
Japan's Keio confirms ransomware attack disrupted business systems
Keio Corporation (Keio), a major private railway operator in Japan, said its network was hit by a ransomware attack over the weekend, disrupting some of its business systems. […]
SRC: BleepingComputer
Mon, 28 Sep 2026 16:56:47 -0400
https://www.bleepingcomputer.com/news/security/japans-keio-confirms-ransomware-attack-disrupted-business-systems/
06
JadePuffer agentic AI attacks target Azure, destroy cloud resources
The JadePuffer ransomware operator is targeting Azure tenants with agent-driven attacks that conduct reconnaissance, steal credentials, and destroy core components. […]
SRC: BleepingComputer
Mon, 28 Sep 2026 11:49:27 -0400
https://www.bleepingcomputer.com/news/security/jadepuffer-agentic-ai-attacks-target-azure-destroy-cloud-resources/
07
Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation
Authorities in the Netherlands have arrested a 23-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters. In the days immediately following the suspect's arrest, remaining ShinyHunters members dramatically escalated their attac
SRC: Krebs on Security
Mon, 28 Sep 2026 15:08:57 +0000
https://krebsonsecurity.com/2026/09/dutch-police-arrest-reformed-hacker-in-shiny-hunters-investigation/
08
Four Cyber Threats Harboring Big Plans for the Future
– AI, supply-chain exposure, quantum computing and geopolitical conflict are testing security programs. Preparing for disruption must become part of day-to-day operations.
The post Four Cyber Threats Harboring Big Plans for the Future appeared first on SecurityWeek.
SRC: SecurityWeek
Tue, 29 Sep 2026 11:30:00 +0000
https://www.securityweek.com/four-cyber-threats-harboring-big-plans-for-the-future/
09
Protego Ventures closes debut $125 million fund for Israeli defense tech
Protego Ventures, the first and largest dedicated defense tech VC in Israel, just completed its final $125 million closing, TechCrunch learned exclusively.
SRC: TechCrunch Security
Tue, 29 Sep 2026 10:00:00 +0000
https://techcrunch.com/2026/09/29/protego-ventures-closes-debut-125-million-fund-for-israeli-defense-tech/
10
Chrome Store Hosts 'Poper Blocker' Spyware Downloaded by Millions
A purported ad-blocker exfiltrates reams of sensitive information and benefits from having Google's stamp of approval despite researcher warnings.
SRC: DarkReading
Mon, 28 Sep 2026 16:51:25 GMT
https://www.darkreading.com/application-security/chrome-store-poper-blocker-spyware-downloaded-millions
11
Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials
A malicious MCP server could trick an application built on the official MCP Python SDK into handing over the OAuth credentials it uses to log in to a real service, the SDK's maintainers said in a security advisory.
Affected versions sent the client secret, the authorization code, and the PKCE proof
SRC: The Hacker News
Tue, 29 Sep 2026 11:38:25 +0530
https://thehackernews.com/2026/09/official-mcp-python-sdk-flaw-can-let.html
12
Carbonato Botnet Puts an AI Agent on Hacked Docker Hosts
The botnet uses the open source Hermes Agent AI framework to execute commands via Telegram and steal AI API keys from exposed Docker hosts.
SRC: DarkReading
Mon, 28 Sep 2026 20:23:58 GMT
https://www.darkreading.com/identity-access-management-security/carbonato-botnet-ai-agent-hacked-docker-hosts
13
JadePuffer AI Actor Compromises Azure Tenant in Destructive Cloud Attack
The "agentic threat actor" may have used exposed credentials to access resources and delete cloud-based storage, applications, and databases.
SRC: DarkReading
Mon, 28 Sep 2026 15:33:21 GMT
https://www.darkreading.com/cloud-security/jadepuffer-ai-actor-azure-tenant-destructive-cloud-attack
14
Times Car confirms data breach affecting 6.6 million user accounts
Japanese car-sharing service Times Car has confirmed that approximately 6.6 million user accounts were compromised in a cyberattack disclosed late last week. […]
SRC: BleepingComputer
Mon, 28 Sep 2026 16:31:16 -0400
https://www.bleepingcomputer.com/news/security/times-car-confirms-data-breach-affecting-66-million-user-accounts/
15
GPT-6 Astra and the Supply Chain Attack It Wasn’t Asked to Launch
UK AISI finds GPT-6 Astra launches unsanctioned supply-chain attacks in simulations far more than earlier OpenAI models, even when told not to. The UK’s AI Security Institute tested GPT-6 Astra before its public release, and the results, published September 28, aren’t subtle. When given a routine cy
SRC: Security Affairs
Tue, 29 Sep 2026 06:27:29 +0000
https://securityaffairs.com/199947/ai/gpt-6-astra-and-the-supply-chain-attack-it-wasnt-asked-to-launch.html
16
IAM for AI agents: A Practical Enterprise Framework
What is IAM for AI agents?
AI agents authenticate, invoke tools, and act across enterprise systems with delegated authority. IAM for AI Agents is the identity-control architecture that governs those actors. This guide covers the limits of conventional provisioning, the components that matter, how t
SRC: The Hacker News
Mon, 28 Sep 2026 23:50:38 +0530
https://thehackernews.com/2026/09/iam-for-ai-agent.html
17
Call for Presentations Open for 2026 CISO Forum Virtual Summit
SecurityWeek seeks original, vendor-neutral presentations that help cybersecurity leaders navigate emerging threats, strengthen resilience, and address the strategic challenges facing today’s enterprise security programs.
The post Call for Presentations Open for 2026 CISO Forum Virtual Summit appear
SRC: SecurityWeek
Mon, 28 Sep 2026 15:15:00 +0000
https://www.securityweek.com/call-for-presentations-open-for-2026-ciso-forum-virtual-summit/
18
Rig Security Emerges From Stealth With $12M to Tackle Agentic AI Identity Risks
Rig provides an identity dependencies graph to distinguish between legitimate users and rogue AI agents
The post Rig Security Emerges From Stealth With $12M to Tackle Agentic AI Identity Risks appeared first on SecurityWeek.
SRC: SecurityWeek
Tue, 29 Sep 2026 12:00:00 +0000
https://www.securityweek.com/rig-security-emerges-from-stealth-with-12m-to-tackle-agentic-ai-identity-risks/
19
OpenAI Calls Off GPT-6.1 Astra Launch, Details Safety Cases for Frontier Training
The GPT-6.1 Astra model was slated to debut in ChatGPT and Codex in October, but it fell short of expectations.
The post OpenAI Calls Off GPT-6.1 Astra Launch, Details Safety Cases for Frontier Training appeared first on SecurityWeek.
SRC: SecurityWeek
Tue, 29 Sep 2026 11:15:59 +0000
https://www.securityweek.com/openai-calls-off-gpt-6-1-astra-launch-details-safety-cases-for-frontier-training/
20
Dutch Police Arrest Convicted Hacker in ShinyHunters Investigation
Pepijn van der Stap was convicted in 2023 for hacking multiple organizations, stealing their data, and extorting them.
The post Dutch Police Arrest Convicted Hacker in ShinyHunters Investigation appeared first on SecurityWeek.
SRC: SecurityWeek
Tue, 29 Sep 2026 11:01:55 +0000
https://www.securityweek.com/dutch-police-arrest-convicted-hacker-in-shinyhunters-investigation/
21
Daemon Tools Hackers’ NeedyMantis Malware Dissected by Microsoft
The malware framework uses a modular architecture and a custom executable file format for long-term persistence.
The post Daemon Tools Hackers’ NeedyMantis Malware Dissected by Microsoft appeared first on SecurityWeek.
SRC: SecurityWeek
Tue, 29 Sep 2026 09:46:13 +0000
https://www.securityweek.com/daemon-tools-hackers-needymantis-malware-dissected-by-microsoft/
Known Exploited — CISA KEV
| CVE | Product | Added to KEV |
|---|---|---|
| CVE-2026-88772 | NetScaler (Citrix) | 2026-09-27 |
| CVE-2026-88771 | NetScaler (Citrix) | 2026-09-27 |
| CVE-2026-67279 | RouterOS (MikroTik) | 2026-09-25 |
| CVE-2026-65660 | SharePoint (Microsoft) | 2026-09-25 |
| CVE-2026-87902 | Core (WordPress) | 2026-09-25 |
| CVE-2026-5430 | Multiple Products (WSO2) | 2026-09-24 |
| CVE-2026-71362 | Commerce and Magento (Adobe) | 2026-09-24 |
| CVE-2026-93952 | VeloCloud Orchestrator (Arista) | 2026-09-22 |
| CVE-2026-94127 | BIG-IP APM (F5) | 2026-09-22 |
| CVE-2026-93616 | Multiple Products (Check Point) | 2026-09-22 |
Indicators of Compromise (IOC)
Download Indicators of Compromise (IOC)
For SOC/NOC ingestion, threat intelligence platforms, and SIEM integration.
