CYBER THREAT INTEL
DAILY BRIEFING · 2026-09-09 12:15 UTC · REPORT BRIEF-20260909-121523
OPEN // LE
PERIOD: LAST 24 HOURS SOURCES: Ars Technica Security, BleepingComputer, Cyber Risk & Security, CyberScoop, DarkReading, Help Net Security
TOP 10 LATEST CYBERSECURITY STORIES from the last 24 hours.
10
Stories Featured
11
Sources
10
Active KEV CVEs
44
IOC Indicators
Top Stories
01
$245 million in stolen crypto funded racketeering crew’s lavish lifestyle
A 22-year-old man built his fortune by breaking into strangers’ digital wallets, then spent it on nightclub tabs, private jets, and a fleet of cars worth millions. Malone Lam, a Singapore citizen, pleaded guilty this week in a Washington D.C. federal court to running a racketeering conspiracy that stole and laundered more than $245 million in cryptocurrency. Lam, who used the aliases “Anne Hathawa
critical
SRC: Help Net Security
Wed, 09 Sep 2026 12:11:36 +0000
https://www.helpnetsecurity.com/2026/09/09/singapore-man-pleads-guilty-245-million-crypto-theft/
02
Hackers Target Claude, Cursor and Codex AI Agents to Steal Tokens and Prompt Histories
Cybercriminals are widening the reach of information-stealing malware by targeting the local data created by AI coding agents. The shift puts access tokens, saved connections, prompt histories, and project records at risk on already infected computers. The activity does not point to a newly discovered flaw in Claude, Cursor, or Codex. Instead, it shows criminals […] The post Hackers Target Claude,
high
SRC: Cyber Risk & Security
Wed, 09 Sep 2026 11:41:29 +0000
https://cybersecuritynews.com/ai-agents-2/
03
DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval
A flaw in DeepSeek Harness, DeepSeek's open-source tool for running AI coding agents on a developer's machine, let a sandboxed agent turn off its own sandbox with a single command. The tool runs an agent's commands inside an operating-system sandbox, so that an agent working on untrusted files cannot write outside its workspace. The agent could remove that limit by calling the tool's own web.
critical
SRC: The Hacker News
Wed, 09 Sep 2026 16:47:07 +0530
https://thehackernews.com/2026/09/deepseek-harness-flaw-let-ai-agents.html
04
Hackers deploy Linux rootkit on F5 BIG-IP APM devices, hiding web shell in memory
A rootkit found on hacked F5 BIG-IP APM devices skips the usual step of writing a web shell to disk, hiding it in memory instead, according to Sophos. F5 BIG-IP APM provides access policy enforcement to secure access to apps, APIs, and data. It’s primarily used by enterprises, financial institutions, government agencies, and public sector organizations. “The implant delivers a familiar outcome – o
critical
SRC: Help Net Security
Wed, 09 Sep 2026 11:05:32 +0000
https://www.helpnetsecurity.com/2026/09/09/f5-big-ip-apm-rootkit-hides-web-shell-in-memory/
05
Man told ChatGPT he was feeling delusional. ChatGPT insisted he was Jesus.
Man with bipolar disorder sued OpenAI after surviving ChatGPT-linked suicide attempt.
medium
SRC: Ars Technica Security
Wed, 09 Sep 2026 11:00:10 +0000
https://arstechnica.com/tech-policy/2026/09/man-told-chatgpt-he-was-feeling-delusional-chatgpt-insisted-he-was-jesus/
06
Hackers Abuse Google Sheets to Hijack Crypto Wallet Addresses in ClickFix Attacks
Hackers are using Google Sheets as an unlikely control channel in a cryptocurrency theft campaign. The operation turns a familiar browser session into a place where malicious code runs, rather than placing a conventional program on a victim’s computer. The attackers promote a fake report claiming to expose profitable flaws at cryptocurrency swap services. Victims […] The post Hackers Abuse Google
high
SRC: Cyber Risk & Security
Wed, 09 Sep 2026 10:57:01 +0000
https://cybersecuritynews.com/hackers-abuse-google-sheets/
07
ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws
AVEVA and Rockwell Automation also released patches for vulnerabilities affecting industrial control system products. The post ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws appeared first on SecurityWeek.
high
SRC: SecurityWeek
Wed, 09 Sep 2026 10:49:30 +0000
https://www.securityweek.com/ics-patch-tuesday-schneider-electric-siemens-fix-critical-flaws/
08
Alby Hub Critical Flaw Could Let Attackers Take Over Internet-Exposed Bitcoin Wallets
Bitcoin wallet company Alby has warned of a critical flaw in Alby Hub that could have let an attacker take over a wallet and send its funds, but only where the owner had made the Hub reachable from the internet. Alby Hub is a self-hosted Lightning wallet, meaning the owner runs it on their own computer or server, and it holds their bitcoin. The flaw affects versions v1.7.0 through.
high
SRC: The Hacker News
Wed, 09 Sep 2026 16:13:04 +0530
https://thehackernews.com/2026/09/alby-hub-critical-flaw-could-let.html
09
Ivanti Patches Critical Flaws Across Enterprise Security Products
Six critical vulnerabilities in Neurons for ITSM could enable remote code execution, while Sentry and EPMM received patches for authentication bypass flaws. The post Ivanti Patches Critical Flaws Across Enterprise Security Products appeared first on SecurityWeek.
critical
SRC: SecurityWeek
Wed, 09 Sep 2026 10:28:34 +0000
https://www.securityweek.com/ivanti-patches-critical-flaws-across-enterprise-security-products/
10
Over 36,000 exposed Plex servers vulnerable to recent flaws
Over 36,000 Plex Media servers exposed online remain unpatched against multiple security vulnerabilities and are vulnerable to attacks. […].
high
SRC: BleepingComputer
Wed, 09 Sep 2026 06:11:29 -0400
https://www.bleepingcomputer.com/news/security/over-36-000-plex-servers-unpatched-against-recently-disclosed-flaws/
Known Exploited — CISA KEV
| CVE | Product | Added to KEV |
|---|---|---|
| CVE-2026-75650 | Commerce and Magento (Adobe) | 2026-09-08 |
| CVE-2026-81963 | Windows (Microsoft) | 2026-09-08 |
| CVE-2026-86218 | N-central (N-able) | 2026-09-08 |
| CVE-2026-85880 | Windows (Microsoft) | 2026-09-08 |
| CVE-2026-85046 | Chromium V8 (Google) | 2026-09-04 |
| CVE-2026-59822 | LiteLLM (BerriAI) | 2026-09-02 |
| CVE-2026-48710 | Starlette (Kludex) | 2026-09-02 |
| CVE-2026-49869 | Kestra OSS (Kestra) | 2026-09-02 |
| CVE-2026-82329 | Artifactory (JFrog) | 2026-09-02 |
| CVE-2026-9586 | Switchvox (Sangoma) | 2026-09-02 |
Indicators of Compromise (IOC)
Download Indicators of Compromise (IOC)
For SOC/NOC ingestion, threat intelligence platforms, and SIEM integration.
