The 48-hour period from September 20-21, 2026 saw significant ransomware activity with 30 organizations publicly listed as victims across multiple threat groups, including major targeting of critical infrastructure and healthcare sectors. A critical CISA KEV entry (CVE-2026-7273) affecting Zyxel GS1900 switches highlights actively exploited vulnerabilities in enterprise network equipment. The npm supply chain ecosystem faces continued threats as attackers evolve techniques to bypass install-script defenses. Multiple critical-severity vulnerabilities (CVSS 10.0) were disclosed affecting D-Link routers and network devices, while a significant data breach exposed 3.2 million Burger King Russia customers through a marketing platform compromise. The Mozi and Mirai botnets remained highly active with 50+ malware distribution URLs detected. Notably, several high-profile organizations including Bruker Corporation, Flex Ltd, and telecommunications provider IKEGAMI TSUSHINKI fell victim to MetaEncryptor and Qilin ransomware groups.
One network device vulnerability added to CISA KEV catalog and multiple critical-severity flaws disclosed affecting routers and web applications
Multiple high-severity WordPress plugin flaws allowing privilege escalation and arbitrary file operations
50 malware distribution URLs detected, primarily Mozi and Mirai botnet variants targeting IoT devices
32 URLs distributing Mozi botnet binaries detected across IP ranges in China, Norway, and other regions. Targets IoT devices via typical bin.sh and Mozi.m payloads
18 URLs serving Mirai variants including bb binary and traditional bin.sh scripts. Infrastructure spans residential IPs suggesting compromised IoT device chain
Evolution of npm supply chain attacks and AI sandbox escape demonstrations
Ongoing campaign involving 'indexed-btree' package demonstrates threat actor adaptation. Malicious code now hidden in normal runtime behavior rather than installation scripts, bypassing common supply chain defenses
Researchers demonstrated two methods to escape OpenAI's Codex sandbox, including running commands on developer machines from most locked-down mode. Both vulnerabilities now patched
30 victim organizations across multiple ransomware groups with significant targeting of healthcare, manufacturing, and critical infrastructure
MetaEncryptor group compromised major corporations including Bruker Corporation (scientific instruments), Flex Ltd (technology manufacturing, Austin TX), Astemo Ltd (80,000 employee automotive parts supplier), and HyVision System Inc (camera module testing equipment)
Multiple healthcare entities compromised including Hudson MD Group LLC (multispecialty medical group, NJ) by MetaEncryptor and TrueCore Behavioral Solutions (youth behavioral treatment, Tampa FL) by Storm ransomware group
Siinqee Bank, Ethiopian financial institution offering inclusive banking services, compromised by LockBit5 variant
Doommageddon ransomware group lists Charlottesville Police Department as upcoming leak (deadline 2026-09-30), representing attack on law enforcement infrastructure
Qilin ransomware compromised Telrad Networks (networking equipment) and IKEGAMI TSUSHINKI Company Limited (broadcast/professional video equipment manufacturer), representing supply chain risks to telecommunications sector
Hogan Lovells Cadwalader compromised by SilentRansomGroup, representing two separate international law firms potentially merged or misidentified in threat actor listing
Major breach exposing 3.2 million customer records through compromised marketing platform
October 2024 breach via Mindbox marketing automation platform compromise exposed 3,155,792 unique email addresses along with names, genders, dates of birth, phone numbers, and approximate geolocations. Data publicly disclosed September 2026
Russian officials report election infrastructure targeting with limited verification
Russian officials claim thousands of cyberattacks on election infrastructure during voting period. Claims could not be independently verified, and officials provided minimal technical evidence or attribution
Advanced approaches to cloud threat emulation and detection engineering
Elastic Security Labs publishes comprehensive plan-first methodology for cloud detection engineering covering scope definition, victim modeling, telemetry requirements, coverage validation, and cleanup. Includes guidance on AI-assisted automation
These briefings are compiled from publicly available threat-intelligence feeds, which may include CISA KEV, NIST NVD, the GitHub Advisory Database (OSV), abuse.ch, and Wordfence Intelligence. Data-breach and credential-leak items may include data from Have I Been Pwned and ransomware.live.
CVE® is a registered trademark of The MITRE Corporation. CVE Records are © The MITRE Corporation, reproduced under the CVE Program Terms of Use. WordPress vulnerability data is provided by Wordfence Intelligence, © Defiant, Inc. Breach data from Have I Been Pwned is licensed under CC BY 4.0.