CYBER THREAT INTEL
DAILY BRIEFING · 2026-09-12 12:15 UTC · REPORT BRIEF-20260912-121530
OPEN // LE
PERIOD: LAST 24 HOURS SOURCES: The Hacker News, Krebs on Security, BleepingComputer, SecurityWeek, Threatpost
TOP 10 LATEST CYBERSECURITY STORIES from the last 24 hours.
5
Stories Featured
5
Sources
10
Active KEV CVEs
28
IOC Indicators
Top Stories
01
GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure
GitLab has released patches to address multiple flaws, including a maximum-severity CVE-2026-85706 (CVSS 10.0), a path traversal issue in the repository commits API. The vulnerability allows unauthenticated users to read arbitrary files from the GitLab server, and in-the-wild probes have been observed within hours of public disclosure.
SRC: The Hacker News
Fri, 11 Sep 2026 22:00:18 +0530
https://thehackernews.com/2026/09/gitlab-cvss-10-file-read-flaw-draws-in.html
02
Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks
Anthropic identified and disrupted industrial-scale illicit distillation attacks against Claude from seven China-based labs, including Alibaba, Moonshot, DeepSeek, Z.ai (Zhipu), and MiniMax. Knowledge distillation is a legitimate ML technique, but these actors abused it at scale to extract proprietary model capabilities for state-aligned AI development.
SRC: The Hacker News
Fri, 11 Sep 2026 21:45:29 +0530
https://thehackernews.com/2026/09/anthropic-says-seven-china-based-ai.html
03
Claude Used to Automate Exploitation and Data Theft Across Multiple Victims
Anthropic warned that cybercriminals and state-sponsored hackers alike are using Claude models for cyber attacks, weapons design, propaganda, and mass surveillance between December 2025 and August 2026. The threat actors, branded as Generative Threat Groups (GTGs), span state-sponsored groups, financially motivated criminals, and commercial hackers.
SRC: The Hacker News
Fri, 11 Sep 2026 19:59:47 +0530
https://thehackernews.com/2026/09/claude-used-to-automate-exploitation.html
04
Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection
Anthropic disrupted a campaign by Russian state-sponsored threat actor GTG-20006 (linked to Midnight Blizzard) that abused Claude for developing an AI-assisted workflow to evade detection. The group used generative AI to rebuild malware variants after detection, demonstrating an evolving APT tactic combining LLMs with traditional cyber espionage.
SRC: The Hacker News
Fri, 11 Sep 2026 19:40:20 +0530
https://thehackernews.com/2026/09/russian-state-sponsored-hackers-use.html
05
OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers
The major malicious attack targeting RubyGems in May 2026 was the work of a swarm of OpenAI agents, according to researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx. On May 12, Mend.io's Maciej Mensfeld disclosed a coordinated cyber attack that targeted the Ruby package manager, gaining remote code execution on RubyDoc documentation servers through an AI-agent-driven campaign.
SRC: The Hacker News
Sat, 12 Sep 2026 14:37:56 +0530
https://thehackernews.com/2026/09/openai-agents-linked-to-rubygems.html
Known Exploited — CISA KEV
| CVE | Product | Added to KEV |
|---|---|---|
| CVE-2026-84869 | ScreenConnect (ConnectWise) | 2026-09-11 |
| CVE-2026-42016 | Artifactory (JFrog) | 2026-09-11 |
| CVE-2026-42018 | Artifactory (JFrog) | 2026-09-11 |
| CVE-2026-85706 | Community Edition and Enterprise Edition (GitLab) | 2026-09-11 |
| CVE-2026-86060 | RouterOS (MikroTik) | 2026-09-10 |
| CVE-2026-67277 | RouterOS (MikroTik) | 2026-09-10 |
| CVE-2026-19490 | NetScaler (Citrix) | 2026-09-09 |
| CVE-2025-25249 | Multiple Products (Fortinet) | 2026-09-09 |
| CVE-2026-87491 | Chromium V8 (Google) | 2026-09-09 |
| CVE-2026-20079 | Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management (Cisco) | 2026-09-09 |
Indicators of Compromise (IOC)
Download Indicators of Compromise (IOC)
For SOC/NOC ingestion, threat intelligence platforms, and SIEM integration.
