CYBER THREAT INTEL
DAILY BRIEFING · 2026-09-26 12:16 UTC · REPORT BRIEF-20260926-121600
OPEN // LE
PERIOD: LAST 24 HOURS SOURCES: Ars Technica Security, BBC Technology, BleepingComputer, BleepingComputer (Google News), Cyber Risk & Security, Cyber Threat Intelligence
TOP 10 LATEST CYBERSECURITY STORIES from the last 24 hours.
18
Stories Featured
53
Sources
10
Active KEV CVEs
28
IOC Indicators
Top Stories
01
Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link
Details have emerged about a high-severity security flaw in the Elementor Website Builder WordPress plugin that could be exploited by an unauthenticated attacker to create rogue administrator accounts and take control of a site.
The cross-site request forgery (CSRF) vulnerability, which has yet to
SRC: The Hacker News
Sat, 26 Sep 2026 15:25:22 +0530
https://thehackernews.com/2026/09/elementor-csrf-flaw-lets-attackers-take.html
02
SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added two security flaws impacting Microsoft SharePoint and Mikrotik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.
The vulnerabilities in question are as follows –
SRC: The Hacker News
Sat, 26 Sep 2026 14:19:53 +0530
https://thehackernews.com/2026/09/sharepoint-rce-and-mikrotik-routeros.html
03
U.S. CISA adds WordPress flaw to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds WordPress flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a WordPress Core flaw, tracked as CVE-2026-87902 (CVSS score of 9.2), to its Known Exploited Vulnera
SRC: Security Affairs
Sat, 26 Sep 2026 07:42:26 +0000
https://securityaffairs.com/199790/security/u-s-cisa-adds-wordpress-flaw-to-its-known-exploited-vulnerabilities-catalog.html
04
Kiteworks urges 6-hour server shutdown over potential zero-day attacks
Secure file-sharing software company Kiteworks is urging customers worldwide to temporarily shut down their servers on Saturday for a six-hour window after receiving threat intelligence warning of a potentially imminent cyberattack. […]
SRC: BleepingComputer
Fri, 25 Sep 2026 17:41:07 -0400
https://www.bleepingcomputer.com/news/security/kiteworks-urges-6-hour-server-shutdown-over-potential-zero-day-attacks/
05
ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw
The Clop ransomware gang has moved its data leak site to a new Tor address after confirming its previous server was compromised and defaced through an unpatched Grav CMS flaw that BleepingComputer has learned is an unauthenticated path traversal vulnerability. […]
SRC: BleepingComputer
Fri, 25 Sep 2026 16:57:55 -0400
https://www.bleepingcomputer.com/news/security/shinyhunters-hacked-clop-leak-site-using-grav-cms-path-traversal-flaw/
06
In Other News: Clop Leak Site Takeover, Docker Botnet Hunts AI Keys, Water Utility Exposure
Noteworthy stories that might have slipped under the radar: BragJack attack against browser AI assistants, TDengine flaw threatens industrial telemetry uptime, Ubuntu update overhaul.
The post In Other News: Clop Leak Site Takeover, Docker Botnet Hunts AI Keys, Water Utility Exposure appeared first
SRC: SecurityWeek
Fri, 25 Sep 2026 15:07:31 +0000
https://www.securityweek.com/in-other-news-clop-leak-site-takeover-docker-botnet-hunts-ai-keys-water-utility-exposure/
07
PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence
Cybersecurity researchers have flagged a new version of PamStealer that ensures that the main payload can only be recovered using a server-side decryption chain.
The latest artifacts, per Jamf Threat Labs, continue to rely on the same JavaScript for Automation (JXA) dropper mechanism, but modify th
SRC: The Hacker News
Fri, 25 Sep 2026 18:48:06 +0530
https://thehackernews.com/2026/09/pamstealer-macos-malware-adds-live-c2.html
08
Cryptocurrency exchange Bitget Says North Korea-Linked Hackers Stole $351.6 Million
Bitget says suspected North Korea-linked actors stole $351.6M from hot and warm wallets. Withdrawals were suspended while Mandiant investigates. Cryptocurrency exchange Bitget says suspected North Korea-linked threat actors stole $351.6 million from a limited number of hot and warm wallets. The comp
SRC: Security Affairs
Fri, 25 Sep 2026 18:02:17 +0000
https://securityaffairs.com/199754/cyber-crime/cryptocurrency-exchange-bitget-says-north-korea-linked-hackers-stole-351-6-million.html
09
North Korea Suspected in $351 Million Bitget Crypto Heist
Bitget’s security systems caught the unauthorized transfers on September 24, and some wallet addresses linked to the attacker have been frozen.
The post North Korea Suspected in $351 Million Bitget Crypto Heist appeared first on SecurityWeek.
SRC: SecurityWeek
Fri, 25 Sep 2026 14:16:18 +0000
https://www.securityweek.com/north-korea-suspected-in-351-million-bitget-crypto-heist/
10
North Korean hackers suspected in $351M crypto theft, the largest so far this year
The $351 million theft from crypto exchange Bitget is the latest in a string of high-profile hacks targeting the crypto sector.
SRC: TechCrunch Security
Fri, 25 Sep 2026 13:24:34 +0000
https://techcrunch.com/2026/09/25/north-korean-hackers-suspected-in-351m-crypto-theft-the-largest-so-far-this-year/
11
Supreme Court permits states to use SAVE database for citizenship checks
Three justices wrote in a dissent that longstanding privacy laws protecting sensitive personal data held by the government should prevent the use of the database.
The post Supreme Court permits states to use SAVE database for citizenship checks appeared first on CyberScoop.
SRC: CyberScoop
Fri, 25 Sep 2026 17:41:12 +0000
https://cyberscoop.com/supreme-court-save-database-voter-citizenship/
12
Anthropic rolls out up to $250 in free Claude Code credits, but only for cloud sessions
Anthropic now allows you to run Claude Code via cloud sessions without signing up for the research preview, and it's offering up to $250 in free usage credits, so more users can give it a try. […]
SRC: BleepingComputer
Fri, 25 Sep 2026 12:00:00 -0400
https://www.bleepingcomputer.com/news/artificial-intelligence/anthropic-rolls-out-up-to-250-in-free-claude-code-credits-but-only-for-cloud-sessions/
13
With the Rise of AI Agents, SOC 2 Should Adapt or Risk Irrelevance
AI agents can operate through human credentials and take actions that existing SOC 2 controls may not distinguish from human activity. Token Security explains why SOC 2 needs to adapt to address the security gaps created by agent identities. […]
SRC: BleepingComputer
Fri, 25 Sep 2026 10:51:10 -0400
https://www.bleepingcomputer.com/news/security/with-the-rise-of-ai-agents-soc-2-should-adapt-or-risk-irrelevance/
14
ClickFix Campaign Abuses Trusted Websites to Deploy Psychedelic Stealer
Attackers hijacked Ukrainian websites to deliver a fake Cloudflare CAPTCHA that installs Psychedelic Stealer and steals browser and crypto credentials. Psychedelic Stealer is being distributed through compromised Ukrainian business websites. Attackers injected hidden iframes into legitimate pages an
SRC: Security Affairs
Fri, 25 Sep 2026 13:49:03 +0000
https://securityaffairs.com/199731/malware/clickfix-campaign-abuses-trusted-websites-to-deploy-psychedelic-stealer.html
15
New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining
The Windows botnet relies on AI to maintain persistence, using xAI Grok to choose from predefined actions.
The post New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining appeared first on SecurityWeek.
SRC: SecurityWeek
Sat, 26 Sep 2026 12:00:00 +0000
https://www.securityweek.com/new-x47-c-windows-botnet-weaponizes-xai-grok-ai-api-draining/
16
OpenAI Says Its Models Engaged With US Government Websites in New Model Misbehavior Disclosure
OpenAI’s CEO said there is an “extensive and ongoing review related to our agents’ use of internet access during training and evaluation.”
The post OpenAI Says Its Models Engaged With US Government Websites in New Model Misbehavior Disclosure appeared first on SecurityWeek.
SRC: SecurityWeek
Sat, 26 Sep 2026 10:15:41 +0000
https://www.securityweek.com/openai-says-its-models-engaged-with-us-government-websites-in-new-model-misbehavior-disclosure/
17
Kiteworks Urges Customers to Shut Down Systems for 9 Hours Over Possible Cyber Attack
Kiteworks (formerly Accellion) is urging customers to shut down their systems as a precautionary measure for nine hours over the weekend after it received threat intelligence about an imminent cyber attack.
"Kiteworks received credible threat intelligence from federal intelligence authorities indic
SRC: The Hacker News
Sat, 26 Sep 2026 13:18:33 +0530
https://thehackernews.com/2026/09/kiteworks-urges-customers-to-shut-down.html
18
AI Sandbox Escapes: Why Forensic Readiness Matters More Than Containment
When autonomous AI agents "escape the sandbox," the real story isn't rogue machines — it's the same access-control failures we've seen for decades.
SRC: DarkReading
Fri, 25 Sep 2026 18:39:32 GMT
https://www.darkreading.com/cyberattacks-data-breaches/ai-sandbox-escapes-forensic-readiness
Known Exploited — CISA KEV
| CVE | Product | Added to KEV |
|---|---|---|
| CVE-2026-67279 | RouterOS (MikroTik) | 2026-09-25 |
| CVE-2026-65660 | SharePoint (Microsoft) | 2026-09-25 |
| CVE-2026-87902 | Core (WordPress) | 2026-09-25 |
| CVE-2026-5430 | Multiple Products (WSO2) | 2026-09-24 |
| CVE-2026-71362 | Commerce and Magento (Adobe) | 2026-09-24 |
| CVE-2026-93952 | VeloCloud Orchestrator (Arista) | 2026-09-22 |
| CVE-2026-94127 | BIG-IP APM (F5) | 2026-09-22 |
| CVE-2026-93616 | Multiple Products (Check Point) | 2026-09-22 |
| CVE-2026-85102 | Multiple Products (Check Point) | 2026-09-22 |
| CVE-2026-7273 | GS1900 Series Switches (Zyxel) | 2026-09-21 |
Indicators of Compromise (IOC)
Download Indicators of Compromise (IOC)
For SOC/NOC ingestion, threat intelligence platforms, and SIEM integration.
