This briefing covers critical security developments from September 14-15, 2026. The period saw active exploitation of a maximum-severity GitLab vulnerability (CVE-2026-85706, CVSS 10.0) affecting supply chains, prompting CISA to add it to their Known Exploited Vulnerabilities catalog. Russian threat actor Sandworm deployed an upgraded Cyclops Blink botnet by chaining Cisco vulnerabilities. Multiple critical vulnerabilities emerged including remote code execution flaws in IBM MQ (CVE-2026-13293), Envoy Gateway path traversal (CVE-2026-53713), and IBM Langflow enabling arbitrary Python execution with root privileges (CVE-2026-12944). Seventeen organizations were added to ransomware leak sites, with the Qilin, Eclipse, and Chaos groups particularly active. Fintech company Revolut disclosed a significant breach where attackers impersonated government agencies to obtain customer financial data and passport information. Additional supply chain risks surfaced with exposed Vite development servers being mass-scanned for cloud credentials, and Microsoft emergency patches addressing Remote Desktop Services failures.
Maximum severity GitLab flaw under active exploitation, plus critical RCE issues in IBM products and development tools
CISA warns that CVE-2026-85706, a maximum severity (CVSS 10.0) path traversal vulnerability affecting GitLab Community and Enterprise Edition, is now being exploited in the wild. This flaw poses significant supply chain risks to organizations using affected GitLab instances.
IBM Langflow OSS versions 1.0.0 through 1.10.0 allow attackers to execute arbitrary Python code with root privileges by submitting components with socket or urllib imports. Enables AWS credential theft via IMDSv1 SSRF and arbitrary system access. CVSS 9.6 (Critical).
Envoy Gateway versions prior to 1.7.4 and 1.8.1 contain a critical path normalization flaw in Lua validator that fails to collapse redundant separators, allowing security policy bypass. CVSS 9.1 (Critical).
Out-of-bounds write vulnerability in multiple Apple platforms (iOS, iPadOS, macOS, tvOS, visionOS, watchOS) addressed with improved bounds checking. Remote attackers can cause unexpected app termination. CVSS 9.8 (Critical).
IBM MQ versions across multiple release lines (9.1.0 through 10.0.0) vulnerable to remote code execution through unsafe deserialization. Remote authenticated attackers can execute arbitrary code on the system. CVSS 8.8 (High).
DevSpace through 6.3.21 fails to validate parent-directory segments in tar entry names from in-pod sync streams. Malicious containers can write arbitrary files on developer workstations, enabling code execution. CVSS 8.8 (High).
Attackers are conducting mass scans targeting internet-exposed Vite development servers to steal AWS and Azure cloud credentials and configurations. This supply chain attack vector exploits misconfigured development environments.
Russian threat actors deploying upgraded botnet infrastructure and pro-Ukraine groups developing new destructive capabilities
Russian APT group Sandworm is distributing an upgraded version of the Cyclops Blink botnet malware by chaining Cisco vulnerabilities. This represents a resurgence of the botnet that FBI disrupted in 2022, now targeting network infrastructure with enhanced capabilities.
The pro-Ukraine hacktivist group Hacking Cat has evolved from website defacements and data leaks to sophisticated destructive attacks against Russian targets. Researchers report deployment of new malware capabilities including ransomware components.
URLhaus reports 50+ new malware distribution URLs primarily serving Mirai and Mozi botnet payloads. IoT devices remain primary targets with continued scanning and exploitation activity across compromised infrastructure.
Black Axe cybercrime group members extradited, multiple APT groups conducting active campaigns
Five members of the Black Axe cybercriminal group have been extradited from South Africa following unsealing of a 2021 indictment. The group conducted lucrative romance scams stealing thousands of dollars from over 100 victims through social engineering tactics.
Coordinated campaign deploying hundreds of fake government websites targeting users across Central Asia. Sites collect victim contact details for follow-on phone and email scams aimed at stealing money, personal information, or gaining device access.
Major fintech breach exposing customer financial data and passports, plus active ransomware campaigns targeting 17 organizations
British fintech Revolut disclosed a data breach after threat actors impersonating government agencies obtained sensitive customer data including financial information, passport details, and identification documents. Attackers submitted fraudulent emergency data requests from legitimate government email accounts.
Japan's Digital Agency discovered a data breach potentially exposing approximately 246,000 rows of government employee personal information due to a VPN vulnerability. The breach affects records containing sensitive personnel data.
Chaos ransomware group leaked 402 GB of confidential corporate, financial, and employee records from Glasfloss. Compromised data includes accounting/finance contracts, ESOP records, and internal documentation across multiple departments.
Silent Ransom Group added prominent law firm Greenberg Traurig to its victim list, affecting 126,000 individuals. The breach follows similar attacks on law firms including Troutman Pepper Locke, representing targeted campaign against legal sector organizations.
Eclipse ransomware group targeted Dublin City Schools charter system in Georgia. The district offers advanced and gifted education, special education, and various support services, potentially exposing student and staff data.
Booba Project ransomware group leaked 37 GB of data from Atlas Ocean Voyages travel arrangements company, potentially including customer booking information and corporate records.
Insomnia ransomware group targeted Metropolitan Community Health Services (Agape Health Services), a FQHC providing primary, preventive, dental, pharmacy, and behavioral health care with sliding-scale services, potentially exposing protected health information.
OAuth abuse, ClickFix campaigns, and cloud identity mapping techniques observed in active attacks
Threat actors compromised HBO Max's official Reddit account to distribute malicious ads launching ClickFix attacks. The campaign delivered information-stealing malware targeting both Windows and macOS devices through social engineering techniques.
Browser extension 'Twitch Enhanced Viewer | JeetBot' with 30,000 installations in Chrome and Firefox stores sends users' Twitch OAuth session tokens to a commercial bot service, enabling account takeover and unauthorized access.
Unit 42 researchers developed a behavioral clustering model to map cloud identity roles from audit logs, enabling continuous threat detection using standard SQL queries. The technique provides automated detection of anomalous cloud access patterns.
Detailed analysis of the critical distinction between Account Logon (authentication) and Logon (resource access) events in Windows Security logs, covering essential Event IDs for Kerberos, NTLM, and RDP sessions for detecting compromises.
Anthropic CEO calls for AI control focus, Google implements controversial search redirect changes
Anthropic CEO Dario Amodei calls for shifting focus from improving frontier AI to controlling it, advocating for slower development pace to allow security and risk prevention efforts to catch up. Significant implications for enterprise AI adoption and security strategies.
Google deployed new search result redirects that prevent users from hovering over links to check destinations before clicking. While Google claims this tackles evolving abuse, security researchers note it removes a key user security control for identifying malicious links.
Homebrew package manager version 7.0.0 released with built-in vulnerability scanner, stronger security controls, and native BrewUI graphical interface, improving security posture for macOS and Linux development environments.
Microsoft emergency patches address RDS failures and USB audio problems from September updates
Microsoft released emergency out-of-band Windows updates to address Remote Desktop Services failures, Hyper-V issues, and USB audio problems caused by September 2026 security updates. Organizations running Windows Server RDS environments should prioritize deployment.
School District of Monroe in Wisconsin experienced a network security incident resulting in internet disconnection, computer shutdown, failed phone service, and canceled ACT testing session. District implementing incident response procedures.
These briefings are compiled from publicly available threat-intelligence feeds, which may include CISA KEV, NIST NVD, the GitHub Advisory Database (OSV), abuse.ch, and Wordfence Intelligence. Data-breach and credential-leak items may include data from Have I Been Pwned and ransomware.live.
CVE® is a registered trademark of The MITRE Corporation. CVE Records are © The MITRE Corporation, reproduced under the CVE Program Terms of Use. WordPress vulnerability data is provided by Wordfence Intelligence, © Defiant, Inc. Breach data from Have I Been Pwned is licensed under CC BY 4.0.