CYBER THREAT INTEL
DAILY BRIEFING · 2026-09-30 12:15 UTC · REPORT BRIEF-20260930-121535
OPEN // LE
PERIOD: LAST 24 HOURS SOURCES: Ars Technica Security, BBC Technology, BleepingComputer, BleepingComputer (Google News), Cyber Risk & Security, Cyber Threat Intelligence
TOP 10 LATEST CYBERSECURITY STORIES from the last 24 hours.
20
Stories Featured
53
Sources
10
Active KEV CVEs
28
IOC Indicators
Top Stories
01
Bitget hacked via zero-day in third-party security products
Cryptocurrency exchange Bitget revealed today that attackers who stole $387.5 million last week breached its systems after exploiting a zero-day flaw in third-party security products. […]
SRC: BleepingComputer
Wed, 30 Sep 2026 07:11:46 -0400
https://www.bleepingcomputer.com/news/security/bitget-hacked-via-zero-day-in-third-party-security-products/
02
Attackers Abuse ChatGPT Custom GPTs to Deploy a Full-Featured RAT
Threat actors abused fake ChatGPT Custom GPTs and ClickFix to deliver a multi-stage RAT. ChatGPT’s Custom GPT feature is the latest legitimate surface being turned into a delivery mechanism, and Huntress researchers caught it in action across at least 40 incidents. A Custom GPT (now simply called a
SRC: Security Affairs
Wed, 30 Sep 2026 09:14:36 +0000
https://securityaffairs.com/200079/ai/attackers-abuse-chatgpt-custom-gpts-to-deploy-a-full-featured-rat.html
03
Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT
Unknown threat actors have been observed exploiting a newly patched security flaw in Citrix NetScaler ADC and NetScaler Gateway appliances to target organizations in North America and Europe.
The activity, observed by Mandiant Consulting and Google Threat Intelligence Group (GTIG) in September 2026
SRC: The Hacker News
Wed, 30 Sep 2026 13:54:35 +0530
https://thehackernews.com/2026/09/attackers-exploit-netscaler-flaw-for.html
04
U.S. CISA adds Apple Multiple Products flaw to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Apple Multiple Products flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an Apple Multiple Products flaw, tracked as CVE-2026-86950 (CVSS score of 8.8), to its
SRC: Security Affairs
Wed, 30 Sep 2026 08:04:32 +0000
https://securityaffairs.com/200069/security/u-s-cisa-adds-apple-multiple-products-flaw-to-its-known-exploited-vulnerabilities-catalog.html
05
South Africa Seeks Help After Cyberattack Targets Air Traffic Control
As aviation infrastructure suffers more cyberattacks, air traffic systems are the latest target, with a ransomware toolkit installed on at least one operational network.
SRC: DarkReading
Wed, 30 Sep 2026 07:00:00 GMT
https://www.darkreading.com/cyberattacks-data-breaches/south-africa-help-cyberattack-air-traffic-control
06
OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted
A High-severity OpenSSL flaw can leak heap memory to the other side of a DTLS connection or crash the program, OpenSSL said on September 29 as it released fixes.
DTLS, the TLS variant used for UDP traffic, resends a handshake message if no reply arrives before the timer expires. The leak or crash c
SRC: The Hacker News
Wed, 30 Sep 2026 13:39:28 +0530
https://thehackernews.com/2026/09/openssl-fixes-high-severity-dtls-flaw.html
07
Japanese railway operators Keio Corporation and Tokyo Metro disclose security breaches
Keio, a major Japanese railway operator, was hit by ransomware, disrupting business systems and forcing the company to shut down its network. Keio Corporation, one of Japan’s major private railway operators, was hit by a ransomware attack over the weekend, disrupting some of its business systems. Th
SRC: Security Affairs
Tue, 29 Sep 2026 20:54:29 +0000
https://securityaffairs.com/200027/data-breach/japanese-railway-operators-keio-corporation-and-tokyo-metro-disclose-security-breaches.html
08
Russian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent Attacks
The state-sponsored group has launched larger-scale phishing campaigns to deploy the CosmicPulse backdoor.
The post Russian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent Attacks appeared first on SecurityWeek.
SRC: SecurityWeek
Wed, 30 Sep 2026 10:59:30 +0000
https://www.securityweek.com/russian-apt-star-blizzard-uses-redflick-infection-chain-in-recent-attacks/
09
ShinyHunters Defiant After FBI Calls on Members to Come Forward
In the wake of a suspected leader’s arrest, ShinyHunters says it never intended to publish data stolen from the FBI.
The post ShinyHunters Defiant After FBI Calls on Members to Come Forward appeared first on SecurityWeek.
SRC: SecurityWeek
Wed, 30 Sep 2026 10:20:02 +0000
https://www.securityweek.com/shinyhunters-defiant-after-fbi-calls-on-members-to-come-forward/
10
'NeedyMantis' Provides Long-Term Access to Compromised Networks
Microsoft observed a China-based actor using a previously unidentified malware framework in targeted intrusions against telcos, universities, medical, and government-related organizations.
SRC: DarkReading
Tue, 29 Sep 2026 15:12:39 GMT
https://www.darkreading.com/threat-intelligence/needymantis-long-term-access-compromised-networks
11
Russian hackers Star Blizzard expand targeting, change up tactics to reach Ukraine and beyond
Microsoft says the cyberespionage campaign has hit U.S. and U.K. targets, relying on sheer volume and requiring only a single victim interaction.
The post Russian hackers Star Blizzard expand targeting, change up tactics to reach Ukraine and beyond appeared first on CyberScoop.
SRC: CyberScoop
Tue, 29 Sep 2026 20:01:44 +0000
https://cyberscoop.com/microsoft-star-blizzard-redflick-phishing-campaigns/
12
AI Coding Agents Exposed 13,000 Internal Images, Including Billing Records, on GitHub
AI coding agents asked to share screenshots of code changes for review have put internal company images in public GitHub repositories, security company Glow said.
Its researchers found more than 13,000 internal images from developers at over 300 organizations, including customer billing records and
SRC: The Hacker News
Wed, 30 Sep 2026 17:00:00 +0530
https://thehackernews.com/2026/09/ai-coding-agents-exposed-13000-internal.html
13
WaterISAC reckons with range of threats after summer of cyberattacks
Internet-exposed tech, PLCs, outside integrators and inside protections are all factors the water sector’s information sharing and analysis center is watching.
The post WaterISAC reckons with range of threats after summer of cyberattacks appeared first on CyberScoop.
SRC: CyberScoop
Wed, 30 Sep 2026 10:00:00 +0000
https://cyberscoop.com/water-utility-cyberattacks-waterisac-cyware-threat-intelligence/
14
French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks
An attacker used stolen passwords of staff at France's tax administration to take tax data on hundreds of thousands of taxpayers and businesses in June and July.
Neither the tax administration nor France's national cybersecurity agency saw the data leave. The attack was not sophisticated, the agenc
SRC: The Hacker News
Tue, 29 Sep 2026 23:17:01 +0530
https://thehackernews.com/2026/09/french-tax-data-theft-using-stolen.html
15
New Spectre v2 attack variant leaks Linux root password hash in minutes
A new Branch Target Reuse (BTR) attack has been devised that can recover root password hashes on Intel computers running Linux in 3-5 minutes on average. […]
SRC: BleepingComputer
Tue, 29 Sep 2026 13:10:11 -0400
https://www.bleepingcomputer.com/news/security/new-spectre-v2-attack-variant-leaks-linux-root-password-hash-in-minutes/
16
101 Malicious npm Packages Add Developers' WhatsApp Accounts to Groups Without Consent
Cybersecurity researchers have identified a cluster of 101 npm packages that are used to trap developers into a WhatsApp group subscriber campaign dubbed PhantomSub.
"The malicious packages abuse the 'Baileys' WhatsApp open source project to add the victims to groups without their consent," OX Secu
SRC: The Hacker News
Tue, 29 Sep 2026 19:15:10 +0530
https://thehackernews.com/2026/09/101-malicious-npm-packages-add.html
17
Anthropic Flags AI Agent Liability Risks as OpenAI Faces Hacking Lawsuit
Attacks by autonomous AI agents are moving out of the lab and into the courtroom, raising unsettled questions about who is liable for what agents do.
The post Anthropic Flags AI Agent Liability Risks as OpenAI Faces Hacking Lawsuit appeared first on SecurityWeek.
SRC: SecurityWeek
Wed, 30 Sep 2026 11:19:00 +0000
https://www.securityweek.com/anthropic-flags-ai-agent-liability-risks-as-openai-faces-hacking-lawsuit/
18
US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access
ANY.RUN researchers traced a US-focused CSuite phishing campaign across 351 sandbox analyses, with 51% of submissions coming from the United States. Technology, manufacturing, government, and consulting organizations showed the highest exposure.
By combining Microsoft 365 session theft with remote-
SRC: The Hacker News
Wed, 30 Sep 2026 16:15:00 +0530
https://thehackernews.com/2026/09/us-focused-csuite-phishing-steals.html
19
Trump Says Top Tech Firms Have Signed Accord to ‘Self-Police’ AI Development
The accord opened the door to future regulation but focused on four voluntary steps for the companies to take.
The post Trump Says Top Tech Firms Have Signed Accord to ‘Self-Police’ AI Development appeared first on SecurityWeek.
SRC: SecurityWeek
Wed, 30 Sep 2026 01:48:21 +0000
https://www.securityweek.com/trump-says-top-tech-firms-have-signed-accord-to-self-police-ai-development/
20
Microsoft is rolling out Linux container support to WSL
Microsoft is taking Windows Subsystem for Linux beyond just running Linux distributions, as WSL Containers is now generally available. […]
SRC: BleepingComputer
Tue, 29 Sep 2026 20:40:57 -0400
https://www.bleepingcomputer.com/news/microsoft/microsoft-is-rolling-out-linux-container-support-to-wsl/
Known Exploited — CISA KEV
| CVE | Product | Added to KEV |
|---|---|---|
| CVE-2026-86950 | Multiple Products (Apple) | 2026-09-29 |
| CVE-2026-88772 | NetScaler (Citrix) | 2026-09-27 |
| CVE-2026-88771 | NetScaler (Citrix) | 2026-09-27 |
| CVE-2026-67279 | RouterOS (MikroTik) | 2026-09-25 |
| CVE-2026-65660 | SharePoint (Microsoft) | 2026-09-25 |
| CVE-2026-87902 | Core (WordPress) | 2026-09-25 |
| CVE-2026-5430 | Multiple Products (WSO2) | 2026-09-24 |
| CVE-2026-71362 | Commerce and Magento (Adobe) | 2026-09-24 |
| CVE-2026-93952 | VeloCloud Orchestrator (Arista) | 2026-09-22 |
| CVE-2026-94127 | BIG-IP APM (F5) | 2026-09-22 |
Indicators of Compromise (IOC)
Download Indicators of Compromise (IOC)
For SOC/NOC ingestion, threat intelligence platforms, and SIEM integration.
