CYBER THREAT INTEL
DAILY BRIEFING · 2026-09-23 12:15 UTC · REPORT BRIEF-20260923-121549
OPEN // LE
PERIOD: LAST 24 HOURS SOURCES: Ars Technica Security, BBC Technology, BleepingComputer, BleepingComputer (Google News), Cyber Risk & Security, Cyber Threat Intelligence
TOP 10 LATEST CYBERSECURITY STORIES from the last 24 hours.
18
Stories Featured
53
Sources
10
Active KEV CVEs
28
IOC Indicators
Top Stories
01
Adobe Patches Critical Flaws in Connect, AEM Forms
The nine critical security defects could be exploited for arbitrary code execution and privilege escalation.
The post Adobe Patches Critical Flaws in Connect, AEM Forms appeared first on SecurityWeek.
SRC: SecurityWeek
Wed, 23 Sep 2026 11:40:59 +0000
https://www.securityweek.com/adobe-patches-critical-flaws-in-connect-aem-forms/
02
EvilTokens made phishing-as-a-service look easy. Then it got taken down
Microsoft, Coinbase and law enforcement took down EvilTokens, a phishing kit that compromised 12,000 inboxes through device-code phishing and AI. EvilTokens showed up in February 2026 and moved fast. Within months it had compromised more than 12,000 inboxes across over 10,000 organizations. Microsof
SRC: Security Affairs
Wed, 23 Sep 2026 11:00:31 +0000
https://securityaffairs.com/199593/cyber-crime/eviltokens-made-phishing-as-a-service-look-easy-then-it-got-taken-down.html
03
Chrome 154 Patches 108 Vulnerabilities
The browser update resolves several critical-severity memory safety and memory corruption flaws.
The post Chrome 154 Patches 108 Vulnerabilities appeared first on SecurityWeek.
SRC: SecurityWeek
Wed, 23 Sep 2026 10:36:07 +0000
https://www.securityweek.com/chrome-154-patches-108-vulnerabilities/
04
Arista Urges Immediate Patching of Exploited VCO Zero-Day
Remote attackers could trigger the critical-severity flaw to access privileged internal functionality.
The post Arista Urges Immediate Patching of Exploited VCO Zero-Day appeared first on SecurityWeek.
SRC: SecurityWeek
Wed, 23 Sep 2026 08:33:06 +0000
https://www.securityweek.com/arista-urges-immediate-patching-of-exploited-vco-zero-day/
05
Ryuk ransomware member sentenced to 24 months in prison
An Armenian man was sentenced to 24 months in prison and 3 years of supervised release for hacking U.S. companies and encrypting their systems in Ryuk ransomware attacks. […]
SRC: BleepingComputer
Wed, 23 Sep 2026 04:20:05 -0400
https://www.bleepingcomputer.com/news/security/ryuk-ransomware-member-sentenced-to-24-months-in-prison/
06
ShinyHunters Claims FBI Hack, Demands Retraction of Threat Report
The cybercrime group is unhappy with its description in an FBI report and threatens to leak stolen information.
The post ShinyHunters Claims FBI Hack, Demands Retraction of Threat Report appeared first on SecurityWeek.
SRC: SecurityWeek
Wed, 23 Sep 2026 07:13:49 +0000
https://www.securityweek.com/shinyhunters-claims-fbi-hack-demands-retraction-of-threat-report/
07
ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants
The cyber extortion group known as ShinyHunters on Tuesday claimed it had breached the U.S. Federal Bureau of Investigation and stolen data belonging to current and former employees at the agency.
"We have compromised the FBI. We hold very sensitive data on almost ALL FBI Agents and individuals who
SRC: The Hacker News
Wed, 23 Sep 2026 11:00:09 +0530
https://thehackernews.com/2026/09/shinyhunters-claims-fbi-breach-says-it.html
08
Relays Are Masking Chinese Access to Frontier AI Models in the US
More than 80,000 AI relay servers are helping users in China mask their identities while they access cutting-edge large language models (LLMs), probably to clone them.
SRC: DarkReading
Tue, 22 Sep 2026 21:12:37 GMT
https://www.darkreading.com/cyber-risk/relays-masking-chinese-access-frontier-ai-models
09
Chinese hackers exploit WordPress, Zyxel flaws to steal govt data
A Chinese-speaking threat actor has been exploiting vulnerabilities in ZyXEL GS1900 Smart Managed Switches and WordPress to steal sensitive data from 996 devices and more than 18,500 records stored in backend databases. […]
SRC: BleepingComputer
Tue, 22 Sep 2026 16:35:24 -0400
https://www.bleepingcomputer.com/news/security/chinese-hackers-exploit-multiple-technologies-to-steal-govt-data/
10
Sweden fines Miljödata $183,000 over breach affecting 2.2 million
Sweden's data privacy regulator, IMY, has imposed a $183,000 (SEK 1.8 million) fine on IT systems provider Miljödata for inadequate security measures leading to a breach in August 2025 affecting 2.2 million people. […]
SRC: BleepingComputer
Tue, 22 Sep 2026 17:40:37 -0400
https://www.bleepingcomputer.com/news/security/sweden-fines-milj-data-183-000-over-breach-affecting-22-million/
11
ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach
The ShinyHunters extortion gang claims it breached FBI systems using a new Oracle PeopleSoft zero-day vulnerability, gaining access to internal services and stealing sensitive data on employees and job applicants. […]
SRC: BleepingComputer
Tue, 22 Sep 2026 15:13:29 -0400
https://www.bleepingcomputer.com/news/security/shinyhunters-claims-fbi-hack-data-theft-in-peoplesoft-zero-day-breach/
12
Hacking group ShinyHunters claims it breached the FBI, stole agents’ and applicants’ data
The theft of agents' personal information could present a major counterintelligence threat, where agents and their families are extorted into cooperating with a foreign government.
SRC: TechCrunch Security
Tue, 22 Sep 2026 18:40:30 +0000
https://techcrunch.com/2026/09/22/hacking-group-shinyhunters-claims-it-breached-the-fbi-stole-agents-and-applicants-data/
13
Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials
Cybersecurity researchers have disclosed details of a malicious npm package named "tw-pkgprobe-7731" that masquerades as a security tool targeting developers integrating Twilio into their applications, while stealthily attempting to harvest sensitive data.
The package, named "tw-pkgprobe-7731," was
SRC: The Hacker News
Tue, 22 Sep 2026 23:28:15 +0530
https://thehackernews.com/2026/09/malicious-npm-package-poses-as-twilio.html
14
Shai-Hulud Attack Nips Cyber-Firm CrowdSec's GitHub Data
Threat actors stole 170 private repositories using an OAuth token stolen from a former employee's computer through the TanStack npm supply chain attack.
SRC: DarkReading
Tue, 22 Sep 2026 17:32:49 GMT
https://www.darkreading.com/cyberattacks-data-breaches/shai-hulud-attack-cyber-firm-crowdsec-github-data
15
UAE, Saudi Arabia Face Onslaught of Increasingly Complex Cyberattacks
The United Arab Emirates and Kingdom of Saudi Arabia together absorbed 50% of all cyberattacks recorded across the Gulf region in the first half of 2026.
SRC: DarkReading
Wed, 23 Sep 2026 16:01:00 GMT
https://www.darkreading.com/threat-intelligence/uae-saudi-arabia-face-onslaught-of-increasingly-sophisticated-automated-cyberattacks
16
AI-Powered Phishing Platform EvilTokens Disrupted by Microsoft
The cybercrime platform leveraged AI at every step of the attack chain, including writing social engineering messages and deciding targets.
The post AI-Powered Phishing Platform EvilTokens Disrupted by Microsoft appeared first on SecurityWeek.
SRC: SecurityWeek
Wed, 23 Sep 2026 11:23:30 +0000
https://www.securityweek.com/ai-powered-phishing-platform-eviltokens-disrupted-by-microsoft/
17
Microsoft: September Windows updates break Always On VPN connections
Microsoft warned that the September 2026 security updates may also break Always On VPN connections on some Windows 11 systems. […]
SRC: BleepingComputer
Wed, 23 Sep 2026 07:18:13 -0400
https://www.bleepingcomputer.com/news/microsoft/microsoft-september-2026-windows-updates-break-always-on-vpn-connections/
18
A Look at AI Doomsday Scenarios That Researchers Say Could Put Humanity at Risk
Debates over the plausibility of these doomsday scenarios have heated up since several executives endorsed slowing the technology’s development for safety reasons.
The post A Look at AI Doomsday Scenarios That Researchers Say Could Put Humanity at Risk appeared first on SecurityWeek.
SRC: SecurityWeek
Wed, 23 Sep 2026 10:20:36 +0000
https://www.securityweek.com/a-look-at-ai-doomsday-scenarios-that-researchers-say-could-put-humanity-at-risk/
Known Exploited — CISA KEV
| CVE | Product | Added to KEV |
|---|---|---|
| CVE-2026-93952 | VeloCloud Orchestrator (Arista) | 2026-09-22 |
| CVE-2026-94127 | BIG-IP APM (F5) | 2026-09-22 |
| CVE-2026-93616 | Multiple Products (Check Point) | 2026-09-22 |
| CVE-2026-85102 | Multiple Products (Check Point) | 2026-09-22 |
| CVE-2026-7273 | GS1900 Series Switches (Zyxel) | 2026-09-21 |
| CVE-2025-39964 | Kernel (Linux) | 2026-09-18 |
| CVE-2026-53266 | Kernel (Linux) | 2026-09-18 |
| CVE-2025-39682 | Kernel (Linux) | 2026-09-18 |
| CVE-2026-58704 | Pixel (Google) | 2026-09-16 |
| CVE-2026-76460 | Identity Services Engine (Cisco) | 2026-09-16 |
Indicators of Compromise (IOC)
Download Indicators of Compromise (IOC)
For SOC/NOC ingestion, threat intelligence platforms, and SIEM integration.
