This 24-hour period reveals a critical surge in targeting of high-value infrastructure and organizations. Most concerning is the confirmed breach of multiple national-scale entities including PayPal support operations (86.7M connection records), AstraZeneca Türkiye (1.35M connections), and Argentina's Ministry of Education (1.08M connections) by the N0n ransomware group, demonstrating sophisticated access to corporate networks and sensitive government systems. Additionally, the Electrolux Group breach by Emperador ransomware threatens a major multinational manufacturer's Azure environment. Critical vulnerabilities dominate the technical landscape, with Cisco's CVE-2026-76460 receiving a perfect 10.0 CVSS score for an authentication bypass in Identity Services Engine, and multiple Totolink router flaws enabling remote buffer overflows. Law enforcement disruptions of Colorado water utilities by foreign actors underscore continuing attacks on critical infrastructure. The Gyazo platform breach exposing 23.6 million user records and new AI-enhanced Android malware (RatHat) capable of autonomously navigating devices to steal banking credentials represent significant consumer threats. Organizations must prioritize patching critical authentication bypass vulnerabilities, implement enhanced monitoring for lateral movement indicators, and reassess third-party risk given the widespread targeting of outsourced operations and supply chain partners.
Multiple critical vulnerabilities with CVSS scores of 9.0+ demand urgent attention, including authentication bypasses and remote code execution flaws in enterprise infrastructure.
Maximum 10.0 CVSS score authentication bypass flaw in Cisco Identity Services Engine (ISE) highlights critical API endpoint authentication issues. Actively exploited zero-day vulnerability.
Three critical buffer overflow vulnerabilities (CVE-2026-93740, CVE-2026-93739, CVE-2026-93738) in Totolink A3002MU router firmware enable remote code execution via submit-url parameter manipulation in formWlEncrypt, formWlAc, and formSchedule. CVSS 10.0 and 9.9. Exploits publicly available.
Unauthenticated access to /api/devfile/ endpoints allows remote attackers to send crafted devfile payloads leading to Server-Side Request Forgery. Console pod can make requests to internal services. CVSS 9.3.
Critical vulnerability in Check Point Software allows attackers to execute code with root privileges on management systems. Security updates released.
IBM Guardium 12.2 affected by critical SQL injection (CVE-2026-84082, CVSS 9.8) enabling unauthenticated remote code execution, plus multiple high-severity flaws including authenticated RCE, privilege escalation, and SUID-root binary exploitation (CVE-2026-84083).
Suricata IDS/IPS versions 7.0-8.0 affected by multiple high-severity vulnerabilities including HTTP/2 buffer retention (CVE-2026-71418), brotli decompression bombs (CVE-2026-63452), FTP transaction overflow (CVE-2026-63447), and MQTT message flooding (CVE-2026-57227). CVSS 7.5-8.2.
CVE-2025-39682: Linux Kernel improper check for unusual/exceptional conditions in TLS receive path allows zero-length records to bypass recvmsg() record-type handling. Newly added to CISA KEV catalog.
CVE-2026-53266 (out-of-bounds write in ebtables SNAT) and CVE-2025-39964 (race condition in AF_ALG socket) added to CISA KEV catalog. Enable kernel exploitation and data corruption. Products may be end-of-life.
Major breaches affecting 23.6M users at Gyazo and widespread ransomware targeting of multinational corporations, government agencies, and critical service providers.
N0n ransomware group breached outsourced PayPal customer support operations in Netherlands/Tunisia. 86.7M connection records of daily support-agent sessions into PayPal corporate Citrix/AAA systems exposed. Complete infrastructure map including internal AD, PKI, Netskope/Zscaler tenants across 8 sites. All sites enforcing network blackout.
N0n ransomware compromised complete internal network-security configuration of all 3 AstraZeneca Turkey sites (940 MB) including every firewall rule, device definition, and remote-access mapping. 1.35M connection records exposing M365/Intune, SAP Concur, UniFi cameras, internal applications. GxP pharmaceutical manufacturing environment.
N0n ransomware breached Argentina's Ministry of Education network. Complete network-security configuration exposed along with 1.08M connection records from national library (BNM), school platforms, scholarship systems, and credential validation systems. Evidence of Monero cryptocurrency infrastructure found.
Emperador ransomware accessed Azure database of Swedish multinational home-appliance manufacturer Electrolux Group and exported all data. Global manufacturer of refrigerators, washing machines, ovens, dishwashers, vacuum cleaners under multiple brands.
Image-sharing platform Gyazo confirmed data breach after hackers exploited server vulnerability to steal 23.6 million user records. Server flaw exploited to exfiltrate complete user database.
N0n ransomware breached Luxembourg-based digital securities platform STOKR. KYC investor register exposed including full names, emails, countries, nationalities, wallet addresses, and tax IDs. Identity-to-crypto-wallet mapping of KYC-accepted investors from France, Germany, Switzerland, Belgium, Netherlands, UK.
N0n ransomware compromised US investment management firm Argentem Creek Partners. 2.5M+ connection records and complete internal systems map (Active Directory, SharePoint, MSP tooling, office-security integrations). Tax-season document flows and investor delivery platforms exposed.
N0n ransomware compromised Venezuela's largest internet provider Inter. 15.3M+ subscriber connection records exposed including tens of thousands of addresses with contacted services. Complete internal network map across all regional operations and core infrastructure configuration.
Navigate360 breach resulted in leak of approximately 94,000 unclassified but sensitive tips submitted through P3 Global Intel apps and websites used by the military. Questions remain about notification and Homeland Security response.
1,894 cases of internal data from Korean heavy ion accelerator 'Raon' (built with $1.08 billion budget) leaked externally by insider. Leak occurred in 2022 but went undetected for 4 years. Radiology and health imaging data.
Foreign state actors and sophisticated threat groups targeting critical infrastructure, government systems, and high-value corporate networks.
Foreign actors breached two small Colorado water utilities (each serving <200 people) in late August and manipulated equipment controlling drinking water systems. Critical infrastructure targeting by foreign threat actors.
Hacking group 'NightEagle' targeting China's high-tech sector has expanded operations to Russia. Kaspersky investigated several incidents at Russian businesses over the past year. APT expanding geographic targeting.
As of July, Vietnam, Laos, Pakistan, and Argentina took meaningful steps to respond to allegations involving North Korean IT worker schemes following October UN study. Coordinated international response to DPRK infiltration operations.
Cyberattack dealt 'critical blow' to International Meteor Organization (IMO) website. Premier international organization responsible for tracking meteors forced to operate via Facebook page with static website notice.
AI-enhanced Android banking malware, new infostealers targeting LastPass users, and North Korean backdoors resurface with expanded targeting beyond cryptocurrency sector.
New Android malware RatHat uses AI to autonomously navigate infected phones while stealing bank logins, authentication codes, and screen-lock PINs. Represents significant evolution in mobile malware capabilities with automated credential theft.
SEO-optimized GitHub repositories impersonate LastPass Authenticator to push previously undocumented infostealer called Rapuncel. Ongoing malware campaign using supply chain poisoning tactics.
North Korean operators built foothold on DevOps engineer's Mac in campaign whose job interview lures deliver malware via Terraform lock files. Expansion beyond cryptocurrency sector targeting infrastructure engineers.
Active Mozi botnet malware distribution targeting MIPS and ARM architectures via multiple compromised hosts. 20+ malware download URLs identified distributing ELF binaries for IoT devices.
Amadey botnet dropping Stealc infostealer via compromised infrastructure. Multi-stage infection chain with automated C2 monitoring.
AppleScript-based ClickFix infostealer targeting macOS users via fake GoogleCert installer (update.googlecert.help). Social engineering leading to credential theft on macOS.
Large-scale Mirai botnet distribution campaign from 94.154.43.241 and 176.65.139.157 targeting multiple architectures (ARM, MIPS, x86, PPC, SH4, etc.) for IoT device compromise.
OAuth consent abuse, AI agent security failures, and authentication bypass techniques highlight evolving attacker methodologies.
Analysis shows MFA cannot replace OAuth governance, least-privilege scopes, consent monitoring, and rapid revocation capabilities. OAuth consent abuse bypasses multi-factor authentication controls.
First confirmed case of AI-driven cyberattack where AI agent autonomously breached Spanish organization and modified personal data. AI-driven attacks transitioning from exotic to mainstream threat vector.
Unit 42 analysis reveals default configurations in AWS AgentCore Harness allow prompt injection to exfiltrate credentials. Uncomfortable space between agent autonomy and identity security.
GHSA-xwmw-prc4-v3cr: Obot OAuth Dynamic Client Registration enables API token theft via audience confusion attack. CVSS 8.8 high-severity vulnerability in go package github.com/obot-platform/obot.
CVE-2026-77339: Process Compose vulnerable to browser DNS rebinding allowing websites to control local process-compose MCP tools. CVSS 5.1 medium severity.
HHS settles HIPAA investigation with genetic testing company and AI safety frameworks released for youth protection.
U.S. Department of Health and Human Services Office for Civil Rights announced settlement with Ambry Genetics Corporation concerning potential HIPAA Security Rule violations. Genetic testing company enforcement action.
Survey of senior AI executives shows organizations rapidly deploying AI and autonomous systems but their processes and controls are not keeping pace. Governance gap in AI deployment.
OpenAI introduces six-pillar Australian Youth Safety Blueprint roadmap for safer AI experiences protecting and empowering young people. AI safety framework for vulnerable populations.
These briefings are compiled from publicly available threat-intelligence feeds, which may include CISA KEV, NIST NVD, the GitHub Advisory Database (OSV), abuse.ch, and Wordfence Intelligence. Data-breach and credential-leak items may include data from Have I Been Pwned and ransomware.live.
CVE® is a registered trademark of The MITRE Corporation. CVE Records are © The MITRE Corporation, reproduced under the CVE Program Terms of Use. WordPress vulnerability data is provided by Wordfence Intelligence, © Defiant, Inc. Breach data from Have I Been Pwned is licensed under CC BY 4.0.