The 48-hour period from September 16-17, 2026 reveals a critical surge in active exploitation and emerging malware campaigns. CISA added a Google Pixel modem vulnerability (CVE-2026-58704) to the KEV catalog while Google simultaneously disclosed active exploitation in limited targeted attacks, representing an immediate patching priority for organizations with Pixel devices in their enterprise environments. A sophisticated banking malware operation using the KREMLIN toolkit has been bypassing browser security controls to force-install credential-stealing Chrome and Edge extensions since mid-2025, while Iranian state-linked actors deployed the CHOSEN BRICK surveillance malware against dissidents and journalists. The ConnectWise ScreenConnect critical vulnerability is now under active exploitation according to CISA, with multiple abuse.ch indicators showing adversaries actively distributing malicious ScreenConnect installers.
Ransomware activity remains intense with 22 new victim disclosures across multiple groups including Akira, Qilin, AuditTeam, and a notable attack against Ukraine's Wise IT system integrator. The data breach landscape includes credential exposure risks from three Ukrainian nationals charged with compromising 610,000 Roblox accounts. Infrastructure threats include a Coast Guard/FBI response to foreign cyber actors attacking an oil tanker in the Gulf of Mexico, demonstrating critical infrastructure targeting. The vulnerability disclosure wave includes 30 high-to-critical severity CVEs spanning multiple platforms, with particularly dangerous authentication bypasses in Feast (CVE-2026-92787), UVdesk (CVE-2026-92805), and djust framework issues (CVE-2026-61594) all rated 9+ CVSS. Microsoft is investigating domain trust relationship failures in Windows 11 KB5124008, potentially impacting enterprise authentication systems.
CISA KEV additions and actively exploited zero-days require immediate response
CISA warns attackers now exploit critical-severity ConnectWise ScreenConnect vulnerability in the wild. Abuse.ch reports multiple malicious ScreenConnect installer distribution campaigns from IPs 144.172.117.212, 217.145.226.120, and 172.86.123.51.
Feast through 0.66.0 fails to verify JWT token signatures before establishing user identity, allowing complete RBAC bypass with hardcoded claim values. Attackers gain unchecked read/write access to feature stores. CVSS 9.8 Critical.
UVdesk Community Skeleton through 1.1.8 allows unauthenticated attackers to repoint database and create super administrator accounts via unprotected wizard endpoints. CVSS 9.8 Critical.
djust Django framework fails to authorize WebSocket/SSE mount path, bypassing LoginRequired decorators and permission checks. CVSS 9.1 Critical - standard Django authorization mechanisms completely bypassed on live transport.
Google Pixel cellular modem contains improper authorization vulnerability allowing privilege escalation. Actively exploited in limited targeted attacks according to Google's September 2026 disclosure. CISA added to KEV catalog requiring federal agency patching.
Craft CMS 4.8.0-4.18.5 and 5.0.0-5.10.12 allows attackers to forge signed redirect parameters using victim's license-shun cookie. HMAC signature not bound to purpose, enabling authentication bypass. CVSS 8.8 High.
Browser extension malware and state-sponsored surveillance targeting activists and enterprises
Banking malware operation active since mid-2025 uses KREMLIN toolkit to force-install malicious Chrome and Edge extensions that steal credentials, session tokens, and sensitive data by bypassing browser integrity checks.
Government agencies warn Iranian state-linked hackers deploy CHOSEN BRICK Windows malware to spy on dissidents, activists, and journalists globally. Sophisticated surveillance capability for monitoring targets of geopolitical interest.
Modern macOS malware campaign uses deceptive installation guides to steal credentials and sensitive user data. Unit 42 analysis reveals evolving tactics for macOS credential theft bypassing Gatekeeper protections.
URLhaus reports 25+ malware download URLs from 176.65.139.152, 176.65.139.145, and 176.65.139.234 distributing Mirai ELF binaries across multiple architectures (ARM, MIPS, x86). Active botnet C2 infrastructure targeting IoT devices.
C2-monitor-auto detects Amadey malware from 91.92.242.236 dropping MSI installers, executables, and CoinMiner payloads. Multi-stage infection chain distributing cryptocurrency mining malware.
Novel browser AI attacks and expanded forensic capabilities
Researchers disclose BragJack attack method that hijacks AI assistants built directly into browsers to access sensitive information, execute malicious actions, and exfiltrate data. New attack surface as browsers integrate LLM agents.
Spanish Data Protection Agency (AEPD) received first notification of attack allegedly carried out using AI agent powered by known large language model. Represents emerging threat of LLM-automated attacks against data systems.
SentinelOne Labs traces suspicious OpenAI agent activity on Hugging Face beyond published timeline. Two accounts reveal staged relay code, internal probes, and ChatGPT account registration indicating undisclosed agent testing or misuse.
Passware Kit adds password recovery and decryption support for Steganos Data Safe v.15 and later including .SHEADER vaults, 2FA, Emergency Passwords, and USB-stored keys. Expanded DFIR capabilities for encrypted container analysis.
Criminal charges and infrastructure targeting
U.S. Coast Guard and FBI boarded oil tanker in Gulf of Mexico after attack by 'foreign cyber actors' to ensure integrity of vessel's operational and IT systems. Critical maritime infrastructure targeted by nation-state adversaries.
Ukrainian authorities preparing trial for three individuals who allegedly stole access to 610,000+ Roblox accounts and sold them to buyers in Russia. Large-scale credential theft operation targeting gaming platform users.
Ukraine's parliament approves tougher criminal penalties for fraudulent call centers and personal data theft following corruption scandal where prosecutors allegedly took bribes to protect scam operations.
22 new ransomware disclosures across multiple groups with notable critical infrastructure targeting
National military forces of Namibia compromised by Ransomhouse ransomware group. Critical government defense organization breach with potential national security implications.
Kyiv-based Ukrainian system integrator providing data center, networking, virtualization, cloud migration, cybersecurity, and software licensing services compromised by AuditTeam ransomware. Partners with Google, Microsoft, VMware, Dell.
Canadian hospital in Nipigon affected by ransomware attack impacting IT systems and patient services. Healthcare sector targeting with potential patient care disruption.
Marketing arm of Alberta and Manitoba honey producer cooperatives compromised by Akira ransomware. Threat actors claim 46GB of corporate data including employee personal information to be released.
Washington DC area contractor providing maintenance, renovation, and painting services compromised. Akira claims 70GB corporate data and employee personal information exfiltration imminent.
Association management firm operating since 1978 compromised by DragonForce ransomware. Over 200GB of data claimed including condominium and planned development management records.
UK optometry practice compromised with 400GB+ patient and business data claimed by DragonForce. Healthcare data breach with sensitive patient eye health information exposure risk.
Thailand's Agricultural Research Development Agency public organization compromised by Arcusmedia ransomware. Government agricultural research data at risk. Deadline: September 23, 2026.
Legislative actions on AI safety, scam prevention, and EU cyber defense coordination
House Energy and Commerce Chairman Brett Guthrie indicates FRONTIER Act on AI safety will wait until 2027, citing complexity and desire to avoid rushed lame duck session legislation. AI governance framework development postponed.
Ursula von der Leyen's State of the Union address emphasizes mounting threats on EU soil, calling for coordinated response to cyberattacks and sabotage following incidents in Denmark, Lithuania, Poland, and Leipzig drone attack attempt.
Radaris.com consumer data broker loses domains in lawsuit alleging New Jersey privacy law violations. Known for ignoring personal information removal requests across people-search empire.
Guarding Unprotected Aging Retirees from Deception Act passes House to equip local law enforcement with scam-fighting tools. Addresses gap where pig butchering and online scams don't reach federal investigation threshold.
Microsoft product issues and enterprise authentication problems
Microsoft investigating reports that Windows 11 KB5124008 security update breaks domain trust relationships on enterprise systems, preventing valid domain credential authentication. Critical enterprise authentication failure.
Microsoft reminds customers Windows Server 2022 reaches end of mainstream support next month, entering extended support until October 2031. Organizations should plan transition to extended support lifecycle phase.
Microsoft investigating known issue causing Copilot and Copilot Chat buttons to disappear for some Windows users in Classic Outlook. Enterprise productivity feature accessibility problem.
These briefings are compiled from publicly available threat-intelligence feeds, which may include CISA KEV, NIST NVD, the GitHub Advisory Database (OSV), abuse.ch, and Wordfence Intelligence. Data-breach and credential-leak items may include data from Have I Been Pwned and ransomware.live.
CVE® is a registered trademark of The MITRE Corporation. CVE Records are © The MITRE Corporation, reproduced under the CVE Program Terms of Use. WordPress vulnerability data is provided by Wordfence Intelligence, © Defiant, Inc. Breach data from Have I Been Pwned is licensed under CC BY 4.0.