CYBER THREAT INTEL
DAILY BRIEFING · 2026-09-11 12:15 UTC · REPORT BRIEF-20260911-121509
OPEN // LE
PERIOD: LAST 24 HOURS SOURCES: BleepingComputer, DarkReading, Wired
TOP 10 LATEST CYBERSECURITY STORIES from the last 24 hours.
10
Stories Featured
3
Sources
10
Active KEV CVEs
28
IOC Indicators
Top Stories
01
GitLab urges users to patch max-severity path traversal vulnerability CVE-2026-85706
GitLab has urgently urged users to patch their servers immediately against a maximum-severity path traversal vulnerability tracked as CVE-2026-85706. The flaw could allow attackers to read or modify files outside the intended directory on affected GitLab instances.
SRC: BleepingComputer
2026-09-11T07:15:22-04:00
https://www.bleepingcomputer.com/news/security/gitlab-urges-users-to-patch-max-severity-path-traversal-flaw/
02
Nightmare-Eclipse strikes again with 'ShieldCrash' Windows Defender zero-day exploit
The disgruntled researcher known as Nightmare-Eclipse has published another zero-day exploit targeting Windows Defender, dubbed 'ShieldCrash.' This continues their ongoing vendetta against Microsoft, further demonstrating the persistent threat from insider-turned-attacker actors.
SRC: DarkReading
2026-09-10T15:29:12Z
https://www.darkreading.com/vulnerabilities-threats/nightmare-eclipse-strikes-again-shieldcrash-windows-exploit
03
New 'BlueMoon' exploit kit deployed against Windows and Chrome zero-day flaws
Multiple cyber-espionage groups have been detected deploying an exploit kit dubbed 'BlueMoon' that leverages zero-day vulnerabilities in both Microsoft Windows and Google Chrome. The kit represents a significant escalation in targeted attacks, combining dual platform exploits in a single distribution framework.
SRC: BleepingComputer
2026-09-10T10:11:34-04:00
https://www.bleepingcomputer.com/news/security/new-bluemoon-kit-exploited-windows-and-chrome-zero-day-flaws/
04
Conti ransomware gang member sentenced to four years in prison
A Ukrainian national has been sentenced to four years in prison for his role in Conti ransomware attacks between 2021 and 2022. The case marks continued international law enforcement efforts to dismantle the notorious ransomware-as-a-service operation that targeted hospitals and critical infrastructure.
SRC: BleepingComputer
2026-09-11T02:48:37-04:00
https://www.bleepingcomputer.com/news/security/conti-ransomware-gang-member-sentenced-to-four-years-in-prison/
05
New Android malware 'Mantax Otax' combines ransomware and spyware capabilities
A new Android malware strain called Mantax Otax has been discovered that combines ransomware and spyware functionality to encrypt files, steal sensitive data, and spam and harass victims. The dual-purpose threat represents an evolution in mobile malware targeting both data theft and financial extortion.
SRC: BleepingComputer
2026-09-10T17:40:43-04:00
https://www.bleepingcomputer.com/news/security/new-android-malware-encrypts-files-steals-data-and-harasses-victims/
06
Cisco FMC vulnerabilities exploited by ransomware gangs and state-sponsored hackers
Cisco Talos has disclosed that two recently patched Secure Firewall Management Center (FMC) vulnerabilities have been exploited in the wild by three separate threat clusters, including those linked to ransomware operations and state-sponsored attacks. Organizations running FMC should apply patches immediately.
SRC: BleepingComputer
2026-09-10T11:43:58-04:00
https://www.bleepingcomputer.com/news/security/cisco-fmc-flaws-exploited-by-ransomware-gang-state-sponsored-hackers/
07
AI-powered attack exploited PaperCut flaws to compromise 395 organizations globally
A threat actor, likely Russian-speaking, used hundreds of AI agents to develop and launch a global exploitation campaign targeting vulnerable PaperCut NG/MF servers across 395 organizations. The use of AI-powered automated reconnaissance and exploitation marks a significant escalation in state-aligned cyber operations.
SRC: BleepingComputer
2026-09-10T11:55:56-04:00
https://www.bleepingcomputer.com/news/security/ai-powered-attack-exploited-papercut-flaws-to-hack-395-organizations/
08
Trezor: 347,000 users targeted in phishing attacks after Brevo data breach
Hardware wallet provider Trezor revealed that phishing attacks against its customers targeted 347,000 email addresses and affected approximately 2,500 users who clicked embedded malicious links. The attacks were enabled by customer data leaked in the Brevo email marketing platform breach, highlighting cascading breach impacts.
SRC: BleepingComputer
2026-09-11T03:55:15-04:00
https://www.bleepingcomputer.com/news/security/trezor-347-000-users-targeted-in-phishing-attacks-after-brevo-breach/
09
Surfshark VPN says hackers breached internal testing and proxy servers
VPN provider Surfshark disclosed that hackers accessed one of its internal test servers after a configuration error exposed it to the internet. While the company stated that no customer data was compromised, the incident raises ongoing questions about VPN security and internal access controls in the privacy sector.
SRC: BleepingComputer
2026-09-10T15:15:07-04:00
https://www.bleepingcomputer.com/news/security/surfshark-vpn-says-hackers-breached-internal-testing-proxy-servers/
10
IDScan confirms breach tied to 153 million stolen driver's license scans
Identity verification company IDScan has confirmed that hackers accessed customer data stored in its cloud platform, days after reports linked the company to a massive database containing over 153 million driver's license scans. The breach exposes highly sensitive personally identifiable information (PII) used for identity verification services nationwide.
SRC: BleepingComputer
2026-09-10T10:55:33-04:00
https://www.bleepingcomputer.com/news/security/idscan-confirms-breach-tied-to-153-million-stolen-drivers-licenses/
Known Exploited — CISA KEV
| CVE | Product | Added to KEV |
|---|---|---|
| CVE-2026-86060 | RouterOS (MikroTik) | 2026-09-10 |
| CVE-2026-67277 | RouterOS (MikroTik) | 2026-09-10 |
| CVE-2026-19490 | NetScaler (Citrix) | 2026-09-09 |
| CVE-2025-25249 | Multiple Products (Fortinet) | 2026-09-09 |
| CVE-2026-87491 | Chromium V8 (Google) | 2026-09-09 |
| CVE-2026-20079 | Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management (Cisco) | 2026-09-09 |
| CVE-2026-75650 | Commerce and Magento (Adobe) | 2026-09-08 |
| CVE-2026-81963 | Windows (Microsoft) | 2026-09-08 |
| CVE-2026-86218 | N-central (N-able) | 2026-09-08 |
| CVE-2026-85880 | Windows (Microsoft) | 2026-09-08 |
Indicators of Compromise (IOC)
Download Indicators of Compromise (IOC)
For SOC/NOC ingestion, threat intelligence platforms, and SIEM integration.
