CYBER THREAT INTEL
DAILY BRIEFING · 2026-09-25 12:15 UTC · REPORT BRIEF-20260925-121536
OPEN // LE
PERIOD: LAST 24 HOURS SOURCES: Ars Technica Security, BBC Technology, BleepingComputer, BleepingComputer (Google News), Cyber Risk & Security, Cyber Threat Intelligence
TOP 10 LATEST CYBERSECURITY STORIES from the last 24 hours.
18
Stories Featured
53
Sources
10
Active KEV CVEs
28
IOC Indicators
Top Stories
01
Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild
The Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability is being actively exploited in the wild.
The vulnerability in question is CVE-2026-48842 (CVSS score: 8.1), a pre-authentication SQL injection in the virtuser_query plugin of Roundcube Webmail versi
SRC: The Hacker News
Fri, 25 Sep 2026 15:44:02 +0530
https://thehackernews.com/2026/09/roundcube-pre-auth-sql-injection-flaw.html
02
U.S. CISA adds Adobe and WSO2 flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Adobe and WSO2 flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: The first
SRC: Security Affairs
Fri, 25 Sep 2026 08:22:47 +0000
https://securityaffairs.com/199704/hacking/u-s-cisa-adds-adobe-and-wso2-flaws-to-its-known-exploited-vulnerabilities-catalog.html
03
Roundcube Webmail Vulnerability in Attackers’ Crosshairs
Tracked as CVE-2026-48842, the exploited bug is an SQL injection that can be exploited without authentication.
The post Roundcube Webmail Vulnerability in Attackers’ Crosshairs appeared first on SecurityWeek.
SRC: SecurityWeek
Fri, 25 Sep 2026 06:57:40 +0000
https://www.securityweek.com/roundcube-webmail-vulnerability-in-attackers-crosshairs/
04
WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical security flaws impacting WSO2 and Adobe Commerce and Magento to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation.
The vulnerabilities are listed below –
C
SRC: The Hacker News
Fri, 25 Sep 2026 10:16:34 +0530
https://thehackernews.com/2026/09/wso2-and-adobe-commerce-flaws-exploited.html
05
3 Cyber Threats That Defined the Summer of 2026
This installment of the Reporters' Notebook video series discusses the impact of AI agents breaching Hugging Face, Fairlife's ransomware attack, and Iranian-linked threat actors compromising a dozen US water systems. It was a busy summer.
SRC: DarkReading
Thu, 24 Sep 2026 14:44:12 GMT
https://www.darkreading.com/cyberattacks-data-breaches/3-cyber-threats-defined-summer-2026
06
FedRAMP VDR & VER: Daily Scans Are Only the Beginning
FedRAMP's new VDR and VER requirements make vulnerability management more continuous, with faster scanning, tighter remediation deadlines, and stronger evidence requirements. Anecdotes explains why the December 7 deadline is just the beginning of a broader shift toward continuous, automated complian
SRC: BleepingComputer
Thu, 24 Sep 2026 10:02:12 -0400
https://www.bleepingcomputer.com/news/security/fedramp-vdr-and-ver-daily-scans-are-only-the-beginning/
07
Russia's Hybrid Cyber-Physical War in Europe Heats Up
A storm is raging in the form of cyber sabotage, disinformation, and drone attacks on European nations, particularly those that provide material support to Ukraine.
SRC: DarkReading
Fri, 25 Sep 2026 07:00:00 GMT
https://www.darkreading.com/physical-security/russia-hybrid-cyber-physical-war-europe
08
Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise
Cryptocurrency exchange Bitget said suspected North Korean threat actors have stolen $351.6 million from its hot and warm wallets.
"At 18:31 UTC on September 24, 2026, Bitget's security systems identified unauthorized transfers involving a limited number of hot wallets," BitGet said in a post shar
SRC: The Hacker News
Fri, 25 Sep 2026 16:05:55 +0530
https://thehackernews.com/2026/09/bitget-says-suspected-north-korean.html
09
Hackers steal $351.6 million in Bitget crypto exchange hack
Cryptocurrency exchange Bitget disclosed today that suspected North Korean hackers have stolen $351.6 million from its hot and warm wallets. […]
SRC: BleepingComputer
Fri, 25 Sep 2026 04:33:44 -0400
https://www.bleepingcomputer.com/news/security/hackers-steal-3516-million-in-bitget-crypto-exchange-hack/
10
House and Senate members propose legislation for CISA to step up cyber defenses for biotech
Biotechnology doesn’t have its own critical infrastructure designation, so the bipartisan group of lawmakers wants to make sure it’s protected like it.
The post House and Senate members propose legislation for CISA to step up cyber defenses for biotech appeared first on CyberScoop.
SRC: CyberScoop
Thu, 24 Sep 2026 21:23:40 +0000
https://cyberscoop.com/biotech-critical-infrastructure-cybersecurity-legislation/
11
Rydox marketplace admin pleads guilty, faces 22 years in prison
A Kosovar national has pleaded guilty to operating Rydox, a large illegal online marketplace that sold stolen personal information, login credentials, credit card details, and cybercrime tools. […]
SRC: BleepingComputer
Fri, 25 Sep 2026 07:35:14 -0400
https://www.bleepingcomputer.com/news/security/rydox-marketplace-admin-pleads-guilty-faces-22-years-in-prison/
12
Windows, Linux, Android File Notification Systems Leak User Activity
Researchers show that file-change notification systems can leak keystroke timing, browsing activity, and WhatsApp media events.
The post Windows, Linux, Android File Notification Systems Leak User Activity appeared first on SecurityWeek.
SRC: SecurityWeek
Fri, 25 Sep 2026 10:53:32 +0000
https://www.securityweek.com/windows-linux-android-file-notification-systems-leak-user-activity/
13
AI-Powered CARBONATO Botnet Steals Credentials to Fund Its Own LLM Gateway
CARBONATO exploits exposed Docker daemons, installs an AI agent, steals API keys and spreads across networks with autonomous command execution. CARBONATO is a Docker-based botnet that has been active since at least October 2024. ThreatDown discovered the operation after finding an unauthenticated co
SRC: Security Affairs
Fri, 25 Sep 2026 09:55:57 +0000
https://securityaffairs.com/199716/malware/ai-powered-carbonato-botnet-steals-credentials-to-fund-its-own-llm-gateway.html
14
‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration
Three vulnerabilities in Salesforce Agentforce allowed hackers to hijack trusted agents, steal data, and launch phishing attacks.
The post ‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration appeared first on SecurityWeek.
SRC: SecurityWeek
Fri, 25 Sep 2026 09:27:51 +0000
https://www.securityweek.com/salesbleed-flaws-in-salesforce-agentforce-enabled-zero-click-data-exfiltration/
15
Microsoft: Recent Windows updates cause desktop loading issues
Microsoft has confirmed that some users may experience desktop loading issues, including black screens, after installing the August 2026 preview updates and subsequent updates. […]
SRC: BleepingComputer
Fri, 25 Sep 2026 06:30:38 -0400
https://www.bleepingcomputer.com/news/microsoft/microsoft-recent-windows-updates-cause-desktop-loading-issues/
16
Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data
A flaw in Cloudflare Containers let a paying customer read data that other customers' containers had left behind on the same server, Cloudflare and the researchers who found it said on Thursday.
The data came from disk space that earlier containers had used and given up, not from any live workload,
SRC: The Hacker News
Fri, 25 Sep 2026 10:19:22 +0530
https://thehackernews.com/2026/09/cloudflare-fixes-flaw-that-let-one.html
17
SectopRAT Returns, Hiding Inside a Legitimate Application
The latest activity from the remote access Trojan (RAT) shows why organizations should monitor the behavior of applications rather than blindly trusting them, experts say.
SRC: DarkReading
Thu, 24 Sep 2026 20:32:50 GMT
https://www.darkreading.com/cyberattacks-data-breaches/sectoprat-returns-hiding-inside-legitimate-application
18
MacSync malware uses public iCloud calendars to deliver new payloads
A new variant of the MacSync malware targeting macOS systems now uses public iCloud calendar events to deliver new native payloads. […]
SRC: BleepingComputer
Thu, 24 Sep 2026 16:53:35 -0400
https://www.bleepingcomputer.com/news/security/macsync-malware-uses-public-icloud-calendars-to-deliver-new-payloads/
Known Exploited — CISA KEV
| CVE | Product | Added to KEV |
|---|---|---|
| CVE-2026-5430 | Multiple Products (WSO2) | 2026-09-24 |
| CVE-2026-71362 | Commerce and Magento (Adobe) | 2026-09-24 |
| CVE-2026-93952 | VeloCloud Orchestrator (Arista) | 2026-09-22 |
| CVE-2026-94127 | BIG-IP APM (F5) | 2026-09-22 |
| CVE-2026-93616 | Multiple Products (Check Point) | 2026-09-22 |
| CVE-2026-85102 | Multiple Products (Check Point) | 2026-09-22 |
| CVE-2026-7273 | GS1900 Series Switches (Zyxel) | 2026-09-21 |
| CVE-2025-39964 | Kernel (Linux) | 2026-09-18 |
| CVE-2026-53266 | Kernel (Linux) | 2026-09-18 |
| CVE-2025-39682 | Kernel (Linux) | 2026-09-18 |
Indicators of Compromise (IOC)
Download Indicators of Compromise (IOC)
For SOC/NOC ingestion, threat intelligence platforms, and SIEM integration.
