CYBER THREAT INTEL
DAILY BRIEFING · 2026-09-18 12:15 UTC · REPORT BRIEF-20260918-121551
OPEN // LE
PERIOD: LAST 24 HOURS SOURCES: Ars Technica Security, BBC Technology, BleepingComputer, BleepingComputer (Google News), Cyber Risk & Security, Cyber Threat Intelligence
TOP 10 LATEST CYBERSECURITY STORIES from the last 24 hours.
17
Stories Featured
53
Sources
10
Active KEV CVEs
28
IOC Indicators
Top Stories
01
Microsoft Patches 18 Vulnerabilities in AI, Cloud Products
Microsoft fixed vulnerabilities across Azure and AI-branded products, with privilege escalation flaws accounting for the majority.
The post Microsoft Patches 18 Vulnerabilities in AI, Cloud Products appeared first on SecurityWeek.
SRC: SecurityWeek
Fri, 18 Sep 2026 10:57:03 +0000
https://www.securityweek.com/microsoft-patches-18-vulnerabilities-in-ai-cloud-products/
02
WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage
Cybersecurity researchers have discovered a cluster of 13 npm packages that have been found to deliver a previously undocumented JavaScript stealer codenamed WeaselBiscuit.
The new malware family, per OpenSourceMalware, exhibits functional overlaps with two malware strains associated with the Democ
SRC: The Hacker News
Fri, 18 Sep 2026 16:10:06 +0530
https://thehackernews.com/2026/09/weaselbiscuit-stealer-spreads-via-13.html
03
New Check Point flaw lets hackers execute code with root privileges
Check Point Software has released security updates to address a critical vulnerability that can let attackers execute code with root privileges on management systems. […]
SRC: BleepingComputer
Fri, 18 Sep 2026 05:34:33 -0400
https://www.bleepingcomputer.com/news/security/check-point-warns-critical-flaw-lets-hackers-execute-code-as-root/
04
Critical Orkes Conductor Vulnerability Exploited in Attacks
CVE-2026-58138 is an unauthenticated remote code execution vulnerability that attackers can exploit via inline workflow definitions.
The post Critical Orkes Conductor Vulnerability Exploited in Attacks appeared first on SecurityWeek.
SRC: SecurityWeek
Fri, 18 Sep 2026 08:42:18 +0000
https://www.securityweek.com/critical-orkes-conductor-vulnerability-exploited-in-attacks/
05
Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer
A financially motivated threat actor has been linked to the development and distribution of a JavaScript (JS)-based information stealer known as PhantomRaven via the npm package registry.
"The developer likely wrote the malware using a large language model (LLM), an assessment made with high confid
SRC: The Hacker News
Fri, 18 Sep 2026 14:48:03 +0530
https://thehackernews.com/2026/09/claimed-bug-bounty-hunter-likely-used.html
06
RatHat Turns Android Accessibility Into an Attack Weapon
RatHat combines AI-driven screen control, Android debugging abuse and advanced credential theft to give attackers deep control of infected phones. RatHat is the new Android trojan you should know about. Zimperium researchers just published a breakdown of a strain they’ve traced to China-based operat
SRC: Security Affairs
Fri, 18 Sep 2026 10:04:52 +0000
https://securityaffairs.com/199317/malware/rathat-turns-android-accessibility-into-an-attack-weapon.html
07
RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall
Cybersecurity researchers have flagged a new Android malware called RatHat that's assessed to be operated by China-based threat actors and features an artificial intelligence (AI)-powered system to navigate and control compromised devices.
"Distributed primarily via targeted smishing (SMS/text phi
SRC: The Hacker News
Fri, 18 Sep 2026 11:47:25 +0530
https://thehackernews.com/2026/09/rathat-android-malware-abuses-adb-to.html
08
China's FamousSparrow APT Spies on US Politics in Latin America
Amid the US and China's fight for eco-colonial influence in Latin America, a stealthy backdoor has taken flight.
SRC: DarkReading
Thu, 17 Sep 2026 19:15:38 GMT
https://www.darkreading.com/cyberattacks-data-breaches/china-famoussparrow-spies-latin-america
09
Cyberattacks on Two Oil Tankers Prompt Coast Guard, FBI to Board Vessels
The Coast Guard confirmed evidence of malicious cyber activity on the VL Prosperity, but has not attributed the attack to Iran.
The post Cyberattacks on Two Oil Tankers Prompt Coast Guard, FBI to Board Vessels appeared first on SecurityWeek.
SRC: SecurityWeek
Thu, 17 Sep 2026 17:09:40 +0000
https://www.securityweek.com/cyberattacks-on-two-oil-tankers-prompt-coast-guard-fbi-to-board-vessels/
10
AI Agent Breaches Spanish Organization, Modifies Personal Data
AI-driven cyberattacks used to be exotic. Soon, it'll be odd if threat actors aren't using agents to do all of their bidding.
SRC: DarkReading
Fri, 18 Sep 2026 07:00:00 GMT
https://www.darkreading.com/cyberattacks-data-breaches/ai-agent-breaches-spanish-organization-personal-data
11
23 Million User Records Compromised in Gyazo Data Breach
Gyazo maker Helpfeel said the attacker exploited a vulnerability in its image upload server to gain unauthorized access.
The post 23 Million User Records Compromised in Gyazo Data Breach appeared first on SecurityWeek.
SRC: SecurityWeek
Fri, 18 Sep 2026 11:38:40 +0000
https://www.securityweek.com/23-million-user-records-compromised-in-gyazo-data-breach/
12
Brevo Supply Chain Attack Injects Malware Into 100,000 Websites
Hackers used a compromised API key to deploy a Cloudflare worker that injected malicious scripts.
The post Brevo Supply Chain Attack Injects Malware Into 100,000 Websites appeared first on SecurityWeek.
SRC: SecurityWeek
Fri, 18 Sep 2026 09:46:57 +0000
https://www.securityweek.com/brevo-supply-chain-attack-injects-malware-into-100000-websites/
13
OpenAI details more cases of AI agents taking unauthorized actions
OpenAI has presented new examples of what they call "AI model misalignment" from the past six months, including unauthorized file uploads, following self-generated instructions, hiding mistakes, and leveraging exposed API keys. […]
SRC: BleepingComputer
Thu, 17 Sep 2026 14:55:12 -0400
https://www.bleepingcomputer.com/news/security/openai-details-more-cases-of-ai-agents-taking-unauthorized-actions/
14
NightmareStresser DDoS Service Disrupted in International Operation
Active since at least 2022, NightmareStresser was one of the longest-running DDoS-for-hire services in the world.
The post NightmareStresser DDoS Service Disrupted in International Operation appeared first on SecurityWeek.
SRC: SecurityWeek
Fri, 18 Sep 2026 10:12:33 +0000
https://www.securityweek.com/nightmarestresser-ddos-service-disrupted-in-international-operation/
15
MIND Secures $72 Million for AI-Powered DLP
The company will use the funding to accelerate platform development and expand its presence in key enterprise markets.
The post MIND Secures $72 Million for AI-Powered DLP appeared first on SecurityWeek.
SRC: SecurityWeek
Fri, 18 Sep 2026 07:25:27 +0000
https://www.securityweek.com/mind-secures-72-million-for-ai-powered-dlp/
16
CISA Ditches Weekly Vulnerability Roundups for Risk-Based Focus
The move is consistent with the agency's advice on the need for organizations to prioritize the vulnerabilities that actually matter.
SRC: DarkReading
Thu, 17 Sep 2026 21:23:50 GMT
https://www.darkreading.com/cyber-risk/cisa-ditches-weekly-vuln-roundups-risk-based-focus
17
OpenAI admits its models lie to cover their own mistakes
OpenAI launches a formal framework to disclose model misalignment, publishing six reports on models that lied, faked data, or bypassed rules. Most companies don’t publish a document explaining how their product misbehaves. OpenAI just did. On September 16, it released a formal framework for tracking
SRC: Security Affairs
Thu, 17 Sep 2026 23:07:21 +0000
https://securityaffairs.com/199302/ai/openai-admits-its-models-lie-to-cover-their-own-mistakes.html
Known Exploited — CISA KEV
| CVE | Product | Added to KEV |
|---|---|---|
| CVE-2026-58704 | Pixel (Google) | 2026-09-16 |
| CVE-2026-76460 | Identity Services Engine (Cisco) | 2026-09-16 |
| CVE-2026-87886 | Backup (Acronis) | 2026-09-16 |
| CVE-2026-76461 | Secure Email Gateway (Cisco) | 2026-09-14 |
| CVE-2026-84869 | ScreenConnect (ConnectWise) | 2026-09-11 |
| CVE-2026-42016 | Artifactory (JFrog) | 2026-09-11 |
| CVE-2026-42018 | Artifactory (JFrog) | 2026-09-11 |
| CVE-2026-85706 | Community Edition and Enterprise Edition (GitLab) | 2026-09-11 |
| CVE-2026-86060 | RouterOS (MikroTik) | 2026-09-10 |
| CVE-2026-67277 | RouterOS (MikroTik) | 2026-09-10 |
Indicators of Compromise (IOC)
Download Indicators of Compromise (IOC)
For SOC/NOC ingestion, threat intelligence platforms, and SIEM integration.
