-
10.86 High
For the latest discoveries in cyber research for the week of 21st Setpember, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Japan’s Digital Agency, which operates the Government Solution Service used by multiple ministries, has confirmed a data breach after attackers exploited a vulnerability in a VPN appliance. Approximately 246,000 records were exposed, […] The post 21st September – Threat Intelligence Report appeared first on Check Point Research .
Why it matters
A zero-day vulnerability is being actively exploited before a vendor patch is available, leaving all unmitigated installations at immediate and unmitigable risk. Attack pattern consistent with adversaries gaining their first foothold in the environment. Coverage across 17 independent sources increases analytical confidence.
MITRE ATT&CK
Technique Name Tactic Confidence T1190 Exploit Public-Facing Application Initial Access Low Countries affected
JapanScore breakdown
Recency 0.320Source Credibility 0.157Corroboration 0.120Severity 0.200Breadth 0.033Actionability 0.027Also reported by
- Check Point Research https://research.checkpoint.com/2026/21st-september-threat-intelligence-report
- ESET WeLiveSecurity https://www.welivesecurity.com/en/kids-online/looking-for-free-robux-heres-whats-real-whats-scam
- Huntress Labs Blog https://www.huntress.com/blog/two-inc-ransom-notes
- Graham Cluley https://www.bitdefender.com/en-us/blog/hotforsecurity/us-coast-guard-fbi-board-oil-tanker-investigate-cyber-attack
- BleepingComputer https://www.bleepingcomputer.com/news/microsoft/windows-11-kb5124010-update-released-with-46-changes-and-fixes
- BBC News Technology https://www.bbc.co.uk/news/articles/c6eq8egl3wd2o?at_medium=RSS&at_campaign=rss
- The New York Times Technology https://www.nytimes.com/2026/09/23/us/politics/ai-us-china-trump-xi-economy.html
- Qualys Security Blog https://blog.qualys.com/category/product-tech
- Malwarebytes Labs https://www.malwarebytes.com/blog/scams/2026/09/fake-parcel-delivery-messages-steal-your-card-and-bank-details
- NBC News Technology https://www.nbcnews.com/business/markets/tech-stocks-bond-yields-oil-tumbles-rcna599082
- The Hacker News https://thehackernews.com/2026/09/cisa-flags-three-linux-kernel.html
- Security Affairs https://securityaffairs.com/199619/security/f5-big-ip-apm-zero-day-exploited-in-zero-day-rce-attacks.html
- ZDNet Security https://www.zdnet.com/innovation/anthropic-claude-opus-5-5-fable-5-1-performance-costs-less
- Infosecurity Magazine https://www.infosecurity-magazine.com/news/ransomware-attacks-reach-record
- Engadget https://www.engadget.com/2267230/everything-announced-at-meta-connect-2026
- Mashable Tech https://mashable.com/entertainment/nyt-connections-hint-answer-today-september-24-2026
Analytical note: ATT&CK technique mappings are inferred from keyword matching and may not reflect confirmed adversary TTPs.
STIX 2.1 Bundle
{ "type": "bundle", "id": "bundle--4aa5f8a2-ecb0-47d5-8b28-6c8a6a16014a", "objects": [ { "type": "report", "spec_version": "2.1", "id": "report--fd204b0f-fc39-4216-bf7f-988abedb0305", "created": "2026-09-24T12:22:07.000Z", "modified": "2026-09-24T12:22:07.000Z", "name": "September 2026 Patch Tuesday: Two Exploited Zero-Days and 113 Critical Vulnerabilities Among 972 CVEs", "description": "For the latest discoveries in cyber research for the week of 21st Setpember, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Japan\u2019s Digital Agency, which operates the Government Solution Service used by multiple ministries, has confirmed a data breach after attackers exploited a vulnerability in a VPN appliance. Approximately 246,000 records were exposed, [\u2026] The post 21st September \u2013 Threat Intelligence Report appeared first on Check Point Research .", "published": "2026-09-24T12:21:50.000Z", "report_types": [ "threat-report" ], "object_refs": [ "attack-pattern--02cd3f7a-2ab7-4028-ab78-b73d79a44e69" ], "external_references": [ { "source_name": "CrowdStrike Blog", "url": "https://www.crowdstrike.com/en-us/blog/patch-tuesday-analysis-september-2026", "description": "September 2026 Patch Tuesday: Two Exploited Zero-Days and 113 Critical Vulnerabilities Among 972 CVEs" } ], "labels": [] }, { "type": "attack-pattern", "spec_version": "2.1", "id": "attack-pattern--02cd3f7a-2ab7-4028-ab78-b73d79a44e69", "created": "2026-09-24T12:22:07.000Z", "modified": "2026-09-24T12:22:07.000Z", "name": "Exploit Public-Facing Application", "external_references": [ { "source_name": "mitre-attack", "external_id": "T1190", "url": "https://attack.mitre.org/techniques/T1190/" } ], "kill_chain_phases": [ { "kill_chain_name": "mitre-attack", "phase_name": "initial-access" } ] } ] } -
Serial Number: AV26-960 Date: September 23, 2026 As of September 23, 2026, Forcepoint is affected by a vulnerability in the following product: Forcepoint Security Engine (NGFW) Versions 7.1.0 to 7.1.13 Versions 7.3.0 to 7.3.1 Version 7.33 Version 7.4.0 to 7.4.1 Version 7.5.0 The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available. Forcepoint Hub Forcepoint Help and Resource Center
Why it matters
An official security advisory has been published. Prompt patching is strongly recommended before adversaries weaponise the disclosed vulnerability. Attack pattern consistent with malicious code running on victim systems. Coverage across 16 independent sources increases analytical confidence.
MITRE ATT&CK
Technique Name Tactic Confidence T1059 Command and Scripting Interpreter Execution Low T1534 Internal Spearphishing Lateral Movement Low Score breakdown
Recency 0.272Source Credibility 0.166Corroboration 0.120Severity 0.200Breadth 0.000Actionability 0.053Also reported by
- Microsoft MSRC https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83498
- CERT-FR (ANSSI) https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1219
- CrowdStrike Blog https://www.crowdstrike.com/en-us/blog/crowdstrike-extends-endpoint-security-to-stop-supply-chain-attacks
- Microsoft Security Blog https://www.microsoft.com/en-us/security/blog/2026/09/17/from-guidance-to-action-security-fundamentals-that-materially-reduce-risk
- Proofpoint Threat Intelligence https://www.proofpoint.com/us/newsroom/press-releases/proofpoint-breaks-down-divide-between-data-security-and-ai-security
- Elastic Security Labs https://www.elastic.co/security-labs/blog/centralized-alert-triage-cross-project-search
- Graham Cluley https://grahamcluley.com/smashing-security-podcast-486
- BleepingComputer https://www.bleepingcomputer.com/news/security/check-point-warns-of-hackers-exploiting-security-gateway-vpn-rce-flaw
- WIRED Security https://www.wired.com/story/metas-muse-ai-agent-zero-day
- SecurityWeek https://www.securityweek.com/ot-security-guidance-nist-drafts-updated-guide-cisa-fbi-advise-on-ics-integrators
- Malwarebytes Labs https://www.malwarebytes.com/blog/bugs/2026/09/update-chrome-108-security-fixes-for-desktop-new-release-for-android
- The Hacker News https://thehackernews.com/2026/09/545-hackers-tested-it-first-now-xranges.html
- Cyber Scoop https://cyberscoop.com/dhs-ig-report-federal-agencies-fail-cisa-cloud-security-directives
- Security Affairs https://securityaffairs.com/199577/malware/fake-lastpass-on-github-led-to-an-infostealer-that-killed-145-security-tools.html
- Help Net Security https://www.helpnetsecurity.com/2026/09/24/azul-intelligence-cloud-ai-assistant
Analytical note: ATT&CK technique mappings are inferred from keyword matching and may not reflect confirmed adversary TTPs. Affected countries could not be determined from available text.
STIX 2.1 Bundle
{ "type": "bundle", "id": "bundle--c1e14361-a911-4386-ac22-19bc6a46a91b", "objects": [ { "type": "report", "spec_version": "2.1", "id": "report--26bf0a39-352e-45ce-aa72-570455b331a5", "created": "2026-09-24T12:22:07.000Z", "modified": "2026-09-24T12:22:07.000Z", "name": "Forcepoint security advisory (AV26-960)", "description": "Serial Number: AV26-960 Date: September 23, 2026 As of September 23, 2026, Forcepoint is affected by a vulnerability in the following product: Forcepoint Security Engine (NGFW) Versions 7.1.0 to 7.1.13 Versions 7.3.0 to 7.3.1 Version 7.33 Version 7.4.0 to 7.4.1 Version 7.5.0 The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available. Forcepoint Hub Forcepoint Help and Resource Center", "published": "2026-09-23T19:11:24.000Z", "report_types": [ "threat-report" ], "object_refs": [ "attack-pattern--a6f0bf8b-99b9-4b51-b9f3-fcf449527487", "attack-pattern--8d84e6ec-2db1-4183-bd03-b1b5bb9ef637" ], "external_references": [ { "source_name": "Canadian Centre for Cyber Security", "url": "https://cyber.gc.ca/en/alerts-advisories/forcepoint-security-advisory-av26-960", "description": "Forcepoint security advisory (AV26-960)" } ], "labels": [] }, { "type": "attack-pattern", "spec_version": "2.1", "id": "attack-pattern--a6f0bf8b-99b9-4b51-b9f3-fcf449527487", "created": "2026-09-24T12:22:07.000Z", "modified": "2026-09-24T12:22:07.000Z", "name": "Command and Scripting Interpreter", "external_references": [ { "source_name": "mitre-attack", "external_id": "T1059", "url": "https://attack.mitre.org/techniques/T1059/" } ], "kill_chain_phases": [ { "kill_chain_name": "mitre-attack", "phase_name": "execution" } ] }, { "type": "attack-pattern", "spec_version": "2.1", "id": "attack-pattern--8d84e6ec-2db1-4183-bd03-b1b5bb9ef637", "created": "2026-09-24T12:22:07.000Z", "modified": "2026-09-24T12:22:07.000Z", "name": "Internal Spearphishing", "external_references": [ { "source_name": "mitre-attack", "external_id": "T1534", "url": "https://attack.mitre.org/techniques/T1534/" } ], "kill_chain_phases": [ { "kill_chain_name": "mitre-attack", "phase_name": "lateral-movement" } ] } ] } -
Serial number: AV26-955 Date: September 23, 2026 As of September 22, 2026, Google published a security advisory to address vulnerabilities in the following product: Stable Channel Chrome for Desktop Versions prior to 154.0.8037.57/.58 (Windows/Mac), and 54.0.8037.57 (Linux) The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.
T1534: Internal Spearphishing TechnologyWhy it matters
An official security advisory has been published. Prompt patching is strongly recommended before adversaries weaponise the disclosed vulnerability. Primary exposure: Technology sector(s). Attack pattern consistent with attackers moving laterally through the network. Coverage across 9 independent sources increases analytical confidence.
MITRE ATT&CK
Technique Name Tactic Confidence T1534 Internal Spearphishing Lateral Movement Low Industries affected
TechnologyScore breakdown
Recency 0.272Source Credibility 0.166Corroboration 0.120Severity 0.200Breadth 0.000Actionability 0.053Also reported by
- CERT-FR (ANSSI) https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1199
- The New York Times Technology https://www.nytimes.com/2026/09/18/technology/google-gemini-ai.html
- WIRED Security https://www.wired.com/story/an-undercover-google-analyst-infiltrated-a-notorious-supply-chain-hacking-gang
- The Guardian Technology https://www.theguardian.com/technology/2026/sep/21/google-is-fined-more-than-400m-by-irish-regulator-over-its-use-of-location-data
- The Hacker News https://thehackernews.com/2026/09/google-fined-403-million-over-gdpr.html
- Cyber Scoop https://cyberscoop.com/volexity-uta0565-china-exploit-chain-chrome-microsoft
- ABC News Technology https://abcnews.com/Technology/wireStory/google-hit-463-million-fine-eu-location-data-136616044
- Help Net Security https://www.helpnetsecurity.com/2026/09/24/google-private-ai-compute-server-side-memory
Analytical note: ATT&CK technique mappings are inferred from keyword matching and may not reflect confirmed adversary TTPs. Affected countries could not be determined from available text.
STIX 2.1 Bundle
{ "type": "bundle", "id": "bundle--05dc3f72-b380-4383-ad07-1ae54e7fc3d1", "objects": [ { "type": "report", "spec_version": "2.1", "id": "report--d0fc9565-96d1-4e97-9711-7bbc33251288", "created": "2026-09-24T12:22:07.000Z", "modified": "2026-09-24T12:22:07.000Z", "name": "Google Chrome security advisory (AV26-955)", "description": "Serial number: AV26-955 Date: September 23, 2026 As of September 22, 2026, Google published a security advisory to address vulnerabilities in the following product: Stable Channel Chrome for Desktop Versions prior to 154.0.8037.57/.58 (Windows/Mac), and 54.0.8037.57 (Linux) The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.", "published": "2026-09-23T17:47:42.000Z", "report_types": [ "threat-report" ], "object_refs": [ "attack-pattern--b8a922d8-55a0-42c4-bc95-7862d5e3db51" ], "external_references": [ { "source_name": "Canadian Centre for Cyber Security", "url": "https://cyber.gc.ca/en/alerts-advisories/google-chrome-security-advisory-av26-955", "description": "Google Chrome security advisory (AV26-955)" } ], "labels": [ "Technology" ] }, { "type": "attack-pattern", "spec_version": "2.1", "id": "attack-pattern--b8a922d8-55a0-42c4-bc95-7862d5e3db51", "created": "2026-09-24T12:22:07.000Z", "modified": "2026-09-24T12:22:07.000Z", "name": "Internal Spearphishing", "external_references": [ { "source_name": "mitre-attack", "external_id": "T1534", "url": "https://attack.mitre.org/techniques/T1534/" } ], "kill_chain_phases": [ { "kill_chain_name": "mitre-attack", "phase_name": "lateral-movement" } ] } ] } -
Threat actors have begun to actively exploit a critical security flaw in WordPress within hours of public disclosure. The vulnerability in question is CVE-2026-87902 (CVSS score: 9.2), which could allow an unauthenticated attacker to obtain remote code execution (RCE). "An unauthenticated attacker can make get_page_template() page-template resolution include a chosen readable local .php file
Why it matters
Covers 1 tracked CVE(s) (CVE-2026-87902) with evidence of active exploitation in the wild—affected software should be patched immediately. Primary exposure: Media sector(s). Attack pattern consistent with malicious code running on victim systems.
MITRE ATT&CK
Technique Name Tactic Confidence T1059 Command and Scripting Interpreter Execution Low Industries affected
MediaScore breakdown
Recency 0.320Source Credibility 0.140Corroboration 0.036Severity 0.200Breadth 0.000Actionability 0.053Analytical note: ATT&CK technique mappings are inferred from keyword matching and may not reflect confirmed adversary TTPs. Affected countries could not be determined from available text.
STIX 2.1 Bundle
{ "type": "bundle", "id": "bundle--b275e10d-12be-498d-808d-5d1c5ca4d4d5", "objects": [ { "type": "report", "spec_version": "2.1", "id": "report--b04b21b9-74df-41d8-bd59-7c1fa41af6e9", "created": "2026-09-24T12:22:07.000Z", "modified": "2026-09-24T12:22:07.000Z", "name": "Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure", "description": "Threat actors have begun to actively exploit a critical security flaw in WordPress within hours of public disclosure. The vulnerability in question is CVE-2026-87902 (CVSS score: 9.2), which could allow an unauthenticated attacker to obtain remote code execution (RCE). \"An unauthenticated attacker can make get_page_template() page-template resolution include a chosen readable local .php file", "published": "2026-09-24T05:36:18.000Z", "report_types": [ "threat-report" ], "object_refs": [ "vulnerability--4b1d88b7-a589-4d30-a1d6-9be3dad59a04", "attack-pattern--af05a666-e031-4f3a-b1ce-51d7c5af6932" ], "external_references": [ { "source_name": "The Hacker News", "url": "https://thehackernews.com/2026/09/attackers-exploit-wordpress-cve-2026.html", "description": "Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure" } ], "labels": [ "Media" ] }, { "type": "vulnerability", "spec_version": "2.1", "id": "vulnerability--4b1d88b7-a589-4d30-a1d6-9be3dad59a04", "created": "2026-09-24T12:22:07.000Z", "modified": "2026-09-24T12:22:07.000Z", "name": "CVE-2026-87902", "external_references": [ { "source_name": "cve", "external_id": "CVE-2026-87902", "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-87902" } ] }, { "type": "attack-pattern", "spec_version": "2.1", "id": "attack-pattern--af05a666-e031-4f3a-b1ce-51d7c5af6932", "created": "2026-09-24T12:22:07.000Z", "modified": "2026-09-24T12:22:07.000Z", "name": "Command and Scripting Interpreter", "external_references": [ { "source_name": "mitre-attack", "external_id": "T1059", "url": "https://attack.mitre.org/techniques/T1059/" } ], "kill_chain_phases": [ { "kill_chain_name": "mitre-attack", "phase_name": "execution" } ] } ] } -
This is an impressive piece of malware . Its sophistication says nation-state to me, but there is no direct evidence and certainly no attribution.
Government MediaWhy it matters
Primary exposure: Government, Media sector(s). Coverage across 6 independent sources increases analytical confidence.
Industries affected
Government MediaScore breakdown
Recency 0.320Source Credibility 0.153Corroboration 0.120Severity 0.120Breadth 0.000Actionability 0.000Also reported by
- The Washington Post Technology https://www.washingtonpost.com/politics/2026/09/23/trump-xi-jinping-will-talk-about-ai-they-arent-close-deal
- BleepingComputer https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-windows-backup-feature-broken-by-september-updates
- Malwarebytes Labs https://www.malwarebytes.com/blog/bugs/2026/09/metas-muse-ai-assistant-has-a-zero-day-that-can-turn-it-into-a-mac-backdoor
- The Hacker News https://thehackernews.com/2026/09/compromised-memtensor-packages-deliver.html
- ABC News Technology https://abcnews.com/Technology/wireStory/ai-doomsday-scenarios-researchers-put-humanity-risk-136675311
Analytical note: Affected countries could not be determined from available text.
STIX 2.1 Bundle
{ "type": "bundle", "id": "bundle--b2e32e07-096e-4aa8-bf86-90f85bbbcc15", "objects": [ { "type": "report", "spec_version": "2.1", "id": "report--1288e70f-1cb9-4c5e-9ea3-de4c3f83591b", "created": "2026-09-24T12:22:07.000Z", "modified": "2026-09-24T12:22:07.000Z", "name": "Malicious npm Packages That Evade Defenses", "description": "This is an impressive piece of malware . Its sophistication says nation-state to me, but there is no direct evidence and certainly no attribution.", "published": "2026-09-24T11:07:42.000Z", "report_types": [ "threat-report" ], "object_refs": [ "report--1288e70f-1cb9-4c5e-9ea3-de4c3f83591b" ], "external_references": [ { "source_name": "Schneier on Security", "url": "https://www.schneier.com/blog/archives/2026/09/malicious-npm-packages-that-evade-defenses.html", "description": "Malicious npm Packages That Evade Defenses" } ], "labels": [ "Government", "Media" ] } ] } -
Information published.
Why it matters
Covers 1 tracked CVE(s) (CVE-2026-87489) with evidence of active exploitation in the wild—affected software should be patched immediately. Coverage across 19 independent sources increases analytical confidence.
Score breakdown
Recency 0.208Source Credibility 0.166Corroboration 0.120Severity 0.200Breadth 0.000Actionability 0.013Also reported by
- CrowdStrike Blog https://www.crowdstrike.com/en-us/blog/crowdstrike-named-leader-forrester-wave-external-threat-intelligence-q3-2026
- ESET WeLiveSecurity https://www.welivesecurity.com/en/business-security/smb-cybersecurity-squeeze-ai-agents-work-old-attacks-overdrive
- Huntress Labs Blog https://www.huntress.com/blog/claude-fable-api-recall
- The Washington Post Technology https://www.washingtonpost.com/technology/2026/09/23/chatbots-still-make-risky-errors-talks-with-teens-about-mental-health
- BleepingComputer https://www.bleepingcomputer.com/news/security/new-remcontrol-android-banking-malware-targets-users-in-europe-and-canada
- Recorded Future News https://www.recordedfuture.com/blog/agent-running-ai
- BBC News Technology https://www.bbc.co.uk/news/articles/c6vgy0333dppo?at_medium=RSS&at_campaign=rss
- The New York Times Technology https://www.nytimes.com/2026/09/17/technology/microsoft-openai-publishing-industry.html
- WIRED Security https://www.wired.com/story/a-tool-for-tracking-ai-integrated-malware-uncovered-an-autonomous-command-system
- The Record (Recorded Future) https://therecord.media/trump-harris-election-meddling-russia
- Securelist (Kaspersky) https://securelist.com/moviereaper-malware-torrent-odyssey-solana/121344
- The Guardian Technology https://www.theguardian.com/technology/2026/sep/21/black-employees-accuse-tesla-fostering-discrimination
- TechCrunch https://techcrunch.com/2026/09/23/youtubes-conversational-video-editing-tool-lets-creators-make-edits-in-natural-language
- The Hacker News https://thehackernews.com/2026/09/anthropic-and-openai-models-still.html
- Dark Reading https://www.darkreading.com/threat-intelligence/attackers-manipulate-ai-chatbots-mass-disinformation-phishing-campaign
- Sky News Technology https://news.sky.com/story/high-levels-of-forever-chemical-causing-cancer-found-in-blood-of-residents-living-near-factory-13591294
- ABC News Technology https://abcnews.com/Technology/wireStory/fulfilling-earlier-us-china-agreements-work-progress-trump-136637799
- Infosecurity Magazine https://www.infosecurity-magazine.com/news/settra-ransomware-retail
Analytical note: Affected countries could not be determined from available text.
STIX 2.1 Bundle
{ "type": "bundle", "id": "bundle--864a70ac-fd13-43ff-891a-6ff62f6a153c", "objects": [ { "type": "report", "spec_version": "2.1", "id": "report--96b23d68-ad56-4855-917f-6d32e8551909", "created": "2026-09-24T12:22:07.000Z", "modified": "2026-09-24T12:22:07.000Z", "name": "Chromium CVE-2026-87489: Memory corruption in V8", "description": "Information published.", "published": "2026-09-23T08:43:17.000Z", "report_types": [ "threat-report" ], "object_refs": [ "vulnerability--f4eab368-51d7-4e6c-a8b3-b2670484e0b9" ], "external_references": [ { "source_name": "Microsoft MSRC", "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87489", "description": "Chromium CVE-2026-87489: Memory corruption in V8" } ], "labels": [] }, { "type": "vulnerability", "spec_version": "2.1", "id": "vulnerability--f4eab368-51d7-4e6c-a8b3-b2670484e0b9", "created": "2026-09-24T12:22:07.000Z", "modified": "2026-09-24T12:22:07.000Z", "name": "CVE-2026-87489", "external_references": [ { "source_name": "cve", "external_id": "CVE-2026-87489", "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-87489" } ] } ] } -
Information published.
Why it matters
Covers 1 tracked CVE(s) (CVE-2026-87536) with evidence of active exploitation in the wild—affected software should be patched immediately. Coverage across 12 independent sources increases analytical confidence.
Score breakdown
Recency 0.208Source Credibility 0.166Corroboration 0.120Severity 0.200Breadth 0.000Actionability 0.013Also reported by
- Proofpoint Threat Intelligence https://www.proofpoint.com/us/newsroom/press-releases/proofpoint-stops-attacks-traditional-defenses-miss-ai-era
- SecurityWeek https://www.securityweek.com/critical-wordpress-vulnerability-exploited-immediately-after-disclosure
- The Record (Recorded Future) https://therecord.media/ransomware-ryuk-sentenced-doj
- The Guardian Technology https://www.theguardian.com/australia-news/2026/sep/24/anthony-albanese-says-openai-agent-hacked-medicare-extreme-concern-sam-altman
- TechCrunch https://techcrunch.com/2026/09/23/vc-firm-bessemer-now-has-another-5-75b-to-invest-in-what-else-ai
- NBC News Technology https://www.nbcnews.com/now/video/fbi-investigating-after-hackers-claim-they-stole-sensitive-data-270392901760
- The Hacker News https://thehackernews.com/2026/09/attackers-use-malicious-terraform.html
- Cyber Scoop https://cyberscoop.com/gottheimer-ai-cyber-defense-act-cisa-pilot
- Security Affairs https://securityaffairs.com/199612/cyber-crime/shinyhunters-claims-fbi-breach-after-alleged-peoplesoft-zero-day-attack.html
- Infosecurity Magazine https://www.infosecurity-magazine.com/news/uk-government-service-led-cyber
- Mashable Tech https://mashable.com/life/target-pokemon-30th-anniversary-event-free-promo-card-how-to-claim
Analytical note: Affected countries could not be determined from available text.
STIX 2.1 Bundle
{ "type": "bundle", "id": "bundle--d72e174e-f552-403d-811d-f05a7bb325a3", "objects": [ { "type": "report", "spec_version": "2.1", "id": "report--359571ed-3dab-4023-b961-4d00ea69aba0", "created": "2026-09-24T12:22:07.000Z", "modified": "2026-09-24T12:22:07.000Z", "name": "Chromium CVE-2026-87536: Use after free in V8", "description": "Information published.", "published": "2026-09-23T08:42:58.000Z", "report_types": [ "threat-report" ], "object_refs": [ "vulnerability--d12d6dcf-a31f-4cca-8c6a-a223d9510c1e" ], "external_references": [ { "source_name": "Microsoft MSRC", "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87536", "description": "Chromium CVE-2026-87536: Use after free in V8" } ], "labels": [] }, { "type": "vulnerability", "spec_version": "2.1", "id": "vulnerability--d12d6dcf-a31f-4cca-8c6a-a223d9510c1e", "created": "2026-09-24T12:22:07.000Z", "modified": "2026-09-24T12:22:07.000Z", "name": "CVE-2026-87536", "external_references": [ { "source_name": "cve", "external_id": "CVE-2026-87536", "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-87536" } ] } ] } -
80.70 Medium
Cybersecurity researchers have disclosed details of an active TeamFiltration campaign codenamed UNK_CondorFiltration that has targeted over 5,700 accounts across 28 Microsoft 365 tenants. According to Proofpoint, the activity has primarily focused on Chilean retail and financial institutions. "The campaign compromised 7 accounts –
Why it matters
Primary exposure: Finance, Technology sector(s). Attack pattern consistent with malicious code running on victim systems. Coverage across 3 independent sources increases analytical confidence.
MITRE ATT&CK
Technique Name Tactic Confidence T1059 Command and Scripting Interpreter Execution Low Industries affected
Finance TechnologyScore breakdown
Recency 0.320Source Credibility 0.140Corroboration 0.084Severity 0.120Breadth 0.033Actionability 0.000Also reported by
Analytical note: ATT&CK technique mappings are inferred from keyword matching and may not reflect confirmed adversary TTPs. Affected countries could not be determined from available text.
STIX 2.1 Bundle
{ "type": "bundle", "id": "bundle--f3d5105e-190f-4f3b-9426-bbe4c7f01ca6", "objects": [ { "type": "report", "spec_version": "2.1", "id": "report--9a06041c-36b9-436e-8817-9a8f37e455b8", "created": "2026-09-24T12:22:07.000Z", "modified": "2026-09-24T12:22:07.000Z", "name": "TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords", "description": "Cybersecurity researchers have disclosed details of an active TeamFiltration campaign codenamed UNK_CondorFiltration that has targeted over 5,700 accounts across 28 Microsoft 365 tenants. According to Proofpoint, the activity has primarily focused on Chilean retail and financial institutions. \"The campaign compromised 7 accounts \u2013", "published": "2026-09-24T06:32:03.000Z", "report_types": [ "threat-report" ], "object_refs": [ "attack-pattern--f626f51d-ab4e-46ec-a1ed-c98f316788e4" ], "external_references": [ { "source_name": "The Hacker News", "url": "https://thehackernews.com/2026/09/teamfiltration-compromises-seven.html", "description": "TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords" } ], "labels": [ "Finance", "Technology" ] }, { "type": "attack-pattern", "spec_version": "2.1", "id": "attack-pattern--f626f51d-ab4e-46ec-a1ed-c98f316788e4", "created": "2026-09-24T12:22:07.000Z", "modified": "2026-09-24T12:22:07.000Z", "name": "Command and Scripting Interpreter", "external_references": [ { "source_name": "mitre-attack", "external_id": "T1059", "url": "https://attack.mitre.org/techniques/T1059/" } ], "kill_chain_phases": [ { "kill_chain_name": "mitre-attack", "phase_name": "execution" } ] } ] } -
New paper: “ Self-Jailbreaking: Language Models Can Reason Themselves Out of Safety Alignment After Benign Reasoning Training .” Abstract: We discover a novel and surprising phenomenon of unintentional misalignment in reasoning language models (RLMs), which we call self-jailbreaking. Specifically, after benign reasoning training on math or code domains, RLMs will use multiple strategies to circumvent their own safety guardrails. To mitigate self-jailbreaking, we find that including minimal safety reasoning data during training is sufficient to ensure RLMs remain safety-aligned.
T1059: Command and Scripting Interpreter GovernmentWhy it matters
Primary exposure: Government sector(s). Attack pattern consistent with malicious code running on victim systems. Coverage across 8 independent sources increases analytical confidence.
MITRE ATT&CK
Technique Name Tactic Confidence T1059 Command and Scripting Interpreter Execution Low Industries affected
GovernmentScore breakdown
Recency 0.208Source Credibility 0.153Corroboration 0.120Severity 0.080Breadth 0.033Actionability 0.027Also reported by
- The Washington Post Technology https://www.washingtonpost.com/technology/2026/09/23/five-indianapolis-officers-charged-following-posts-reporting-flock-misuse
- The Guardian Technology https://www.theguardian.com/technology/2026/sep/21/stop-relying-on-chatbots-for-customer-care-uk-service-providers-urged
- NBC News Technology https://www.nbcnews.com/politics/trump-administration/cnn-politico-ms-now-plan-sue-trump-administration-ban-white-house-cove-rcna598912
- The Hacker News https://thehackernews.com/2026/09/windows-malware-is-built-to-let-up-to.html
- Cyber Scoop https://cyberscoop.com/openai-ukraine-cybersecurity-critical-infrastructure
- ABC News Technology https://abcnews.com/Technology/wireStory/agency-sea-turtle-eggs-laid-california-beaches-us-136664710
- Mashable Tech https://mashable.com/tech/8bitdo-ultimate-3-lavender-dusk-xbox-controller-launch
Analytical note: ATT&CK technique mappings are inferred from keyword matching and may not reflect confirmed adversary TTPs. Affected countries could not be determined from available text.
STIX 2.1 Bundle
{ "type": "bundle", "id": "bundle--3edad3ff-ae7a-470f-9ec2-24a8afd158a2", "objects": [ { "type": "report", "spec_version": "2.1", "id": "report--e8b09500-b751-45ba-9820-7afac2e71679", "created": "2026-09-24T12:22:07.000Z", "modified": "2026-09-24T12:22:07.000Z", "name": "Research on Models Engaging in Genie-Like Behavior", "description": "New paper: \u201c Self-Jailbreaking: Language Models Can Reason Themselves Out of Safety Alignment After Benign Reasoning Training .\u201d Abstract: We discover a novel and surprising phenomenon of unintentional misalignment in reasoning language models (RLMs), which we call self-jailbreaking. Specifically, after benign reasoning training on math or code domains, RLMs will use multiple strategies to circumvent their own safety guardrails. To mitigate self-jailbreaking, we find that including minimal safety reasoning data during training is sufficient to ensure RLMs remain safety-aligned.", "published": "2026-09-23T11:03:36.000Z", "report_types": [ "threat-report" ], "object_refs": [ "attack-pattern--ef537c77-75e9-4701-ae31-12d14a8956fb" ], "external_references": [ { "source_name": "Schneier on Security", "url": "https://www.schneier.com/blog/archives/2026/09/research-on-models-engaging-in-genie-like-behavior.html", "description": "Research on Models Engaging in Genie-Like Behavior" } ], "labels": [ "Government" ] }, { "type": "attack-pattern", "spec_version": "2.1", "id": "attack-pattern--ef537c77-75e9-4701-ae31-12d14a8956fb", "created": "2026-09-24T12:22:07.000Z", "modified": "2026-09-24T12:22:07.000Z", "name": "Command and Scripting Interpreter", "external_references": [ { "source_name": "mitre-attack", "external_id": "T1059", "url": "https://attack.mitre.org/techniques/T1059/" } ], "kill_chain_phases": [ { "kill_chain_name": "mitre-attack", "phase_name": "execution" } ] } ] } -
We look at a new version of the MacSync macOS stealer with a backdoor module that targets crypto enthusiasts and developers.
Finance TechnologyWhy it matters
Primary exposure: Finance, Technology sector(s).
Industries affected
Finance TechnologyScore breakdown
Recency 0.320Source Credibility 0.144Corroboration 0.036Severity 0.120Breadth 0.000Actionability 0.000Analytical note: Affected countries could not be determined from available text.
STIX 2.1 Bundle
{ "type": "bundle", "id": "bundle--50c4c6c7-806b-45e8-8130-94fe86f5fe2f", "objects": [ { "type": "report", "spec_version": "2.1", "id": "report--4697177d-94da-45fd-b3a8-f038fb55cac6", "created": "2026-09-24T12:22:07.000Z", "modified": "2026-09-24T12:22:07.000Z", "name": "MacSync under the microscope: new delivery methods and a new payload", "description": "We look at a new version of the MacSync macOS stealer with a backdoor module that targets crypto enthusiasts and developers.", "published": "2026-09-24T10:00:21.000Z", "report_types": [ "threat-report" ], "object_refs": [ "report--4697177d-94da-45fd-b3a8-f038fb55cac6" ], "external_references": [ { "source_name": "Securelist (Kaspersky)", "url": "https://securelist.com/macsync-new-version/121383", "description": "MacSync under the microscope: new delivery methods and a new payload" } ], "labels": [ "Finance", "Technology" ] } ] }
-
OpenAI agents targeted public data providers in multiple countries, probing some for vulnerabilities and exploiting a security weakness in an Australian government portal while performing information-retrieval tasks as part of a research project.
Why it matters
Reported by BleepingComputer. Full significance assessment requires additional corroborating data.
Score breakdown
Recency 0.400Source Credibility 0.082Corroboration 0.090Severity 0.050Breadth 0.033Actionability 0.017Analytical note: Affected countries could not be determined from available text.
-
The disclosure comes as world leaders meet at the United Nations General Assembly this week to discuss topics including AI security.
Why it matters
A confirmed data incident indicates adversaries achieved persistent access and likely exfiltrated data, with downstream exposure risk for affected users and partners. Independently corroborated by a second source.
Score breakdown
Recency 0.340Source Credibility 0.080Corroboration 0.150Severity 0.050Breadth 0.017Actionability 0.000Also reported by
Analytical note: Affected countries could not be determined from available text.
-
ShinyHunters, a cyber-extortion outfit, said it hacked into the FBI’s jobs portal and used that access to steal a major tranche of sensitive files.
Why it matters
A confirmed data incident indicates adversaries achieved persistent access and likely exfiltrated data, with downstream exposure risk for affected users and partners. Independently corroborated by a second source.
Score breakdown
Recency 0.340Source Credibility 0.079Corroboration 0.150Severity 0.050Breadth 0.000Actionability 0.017Also reported by
Analytical note: Affected countries could not be determined from available text.
-
Hackers impersonated the company’s personnel and contacted its employees to gain access to Astrana Health’s servers. The post Astrana Health Data Breach Impacts Private, Confidential Information appeared first on SecurityWeek .
Why it matters
A confirmed data incident indicates adversaries achieved persistent access and likely exfiltrated data, with downstream exposure risk for affected users and partners.
Score breakdown
Recency 0.400Source Credibility 0.080Corroboration 0.090Severity 0.050Breadth 0.000Actionability 0.000Analytical note: Affected countries could not be determined from available text.
-
Latvian police arrested a 23-year-old man suspected of hacking at least two companies, stealing personal information and attempting to extort money from the victims.
GovernmentWhy it matters
A confirmed data incident indicates adversaries achieved persistent access and likely exfiltrated data, with downstream exposure risk for affected users and partners. Primary exposure: Government sector(s).
Industries affected
GovernmentScore breakdown
Recency 0.340Source Credibility 0.080Corroboration 0.090Severity 0.075Breadth 0.000Actionability 0.017Analytical note: Affected countries could not be determined from available text.
-
In each incident, the technology appeared to be conducting mundane data collection and resorted to hacking techniques to get it, researchers said.
Why it matters
A confirmed data incident indicates adversaries achieved persistent access and likely exfiltrated data, with downstream exposure risk for affected users and partners.
Score breakdown
Recency 0.400Source Credibility 0.082Corroboration 0.090Severity 0.025Breadth 0.000Actionability 0.000Analytical note: Affected countries could not be determined from available text.
-
Karen Vardanyan has also been ordered to pay over $1.2 million in restitution to victims. The post US Court Sentences Armenian Man to Prison for Ryuk Ransomware Attacks appeared first on SecurityWeek .
Ryuk United StatesWhy it matters
Active Ryuk ransomware campaign—organisations face immediate risk of data encryption, operational disruption, and potential extortion demands. Attack pattern consistent with destructive actions targeting systems or data.
Countries affected
United StatesScore breakdown
Recency 0.400Source Credibility 0.080Corroboration 0.090Severity 0.025Breadth 0.000Actionability 0.000Analytical note: ATT&CK technique mappings are inferred from keyword matching and may not reflect confirmed adversary TTPs.
-
A convincing offer of a free Claude Max subscription uses a fake browser window to steal Google login information.
TechnologyWhy it matters
Primary exposure: Technology sector(s). Attack pattern consistent with adversaries gaining their first foothold in the environment. Independently corroborated by a second source.
Industries affected
TechnologyScore breakdown
Recency 0.340Source Credibility 0.080Corroboration 0.150Severity 0.025Breadth 0.000Actionability 0.000Also reported by
Analytical note: ATT&CK technique mappings are inferred from keyword matching and may not reflect confirmed adversary TTPs. Affected countries could not be determined from available text.
-
The logistics sector has become the target of a new malicious cyber campaign that distributes an Android spyware codenamed Corp MDM. According to Have I Been Squatted, the campaign uses fake Google Play pages branded as CEVA and TKW Logistics to distribute an Android Package Kit (APK) file that's dressed up as a system service. The delivered app has the package name "com.corp.mdm" Corp MDM
Play Technology TransportWhy it matters
Involves Play, a established malware family with confirmed operational history and significant impact potential. Primary exposure: Technology, Transport sector(s). Attack pattern consistent with attackers moving laterally through the network. Associated (low confidence) with known threat actor Play.
Attribution
- Play Low confidence Named in: The Hacker News
Industries affected
Technology TransportScore breakdown
Recency 0.400Source Credibility 0.078Corroboration 0.090Severity 0.000Breadth 0.000Actionability 0.000Analytical note: Attribution is derived from public reporting only and should be treated as preliminary. ATT&CK technique mappings are inferred from keyword matching and may not reflect confirmed adversary TTPs. Affected countries could not be determined from available text.
-
The Justice Department has a long history of investigating and prosecuting hackers who break into a private company’s network
Why it matters
Reported by ABC News Technology. Full significance assessment requires additional corroborating data.
Score breakdown
Recency 0.400Source Credibility 0.077Corroboration 0.090Severity 0.000Breadth 0.000Actionability 0.000Analytical note: Affected countries could not be determined from available text.
No threats match your filter.