The 48-hour period from September 22-23, 2026 witnessed significant threat activity across multiple fronts. Most notably, the ShinyHunters extortion gang claimed a major breach of FBI systems using a zero-day vulnerability in Oracle PeopleSoft, allegedly accessing employee and job applicant data. Microsoft disrupted the EvilTokens phishing-as-a-service platform after it compromised over 12,000 Microsoft 365 accounts across 10,000+ organizations using AI-assisted device code phishing. Two UK arrests followed this takedown. Critical zero-day vulnerabilities emerged in Check Point Security Management Server (CVE-2026-93616, exploited in the wild), D-Link DIR-822A routers (CVE-2026-86296, maximum severity with public PoC), and Windows Defender (blocking antivirus updates). Chinese threat actors actively exploited Zyxel GS1900 switch vulnerabilities to exfiltrate data from 996 devices. CISA added four vulnerabilities to the KEV catalog, including the exploited Zyxel flaw and Check Point issues. New AI-powered malware named ClosedQuorum uses Google Gemini and other AI models for autonomous attack decision-making. Ransomware groups remained highly active with 30 newly disclosed victims including major targets like Brazil's Federal Revenue Service (Receita Federal), Oman's Asyad Group logistics provider, and Fresenius Medical Care. The threat landscape shows adversaries rapidly weaponizing AI capabilities while nation-state actors continue infrastructure exploitation campaigns.
Multiple critical and actively exploited vulnerabilities including Check Point zero-days, D-Link router flaws, and Windows Defender issues
Check Point Security Management Server contains a path traversal vulnerability allowing unauthenticated attackers to upload and execute arbitrary scripts. This vulnerability is being actively exploited in the wild and was added to CISA KEV catalog.
D-Link warned of a maximum-severity (10.0 CVSS) vulnerability affecting legacy DIR-822A dual-band Wi-Fi routers with public proof-of-concept exploit code available and no patch planned. Immediate device replacement recommended.
Check Point Security Gateway and Spark Firewall VPN products contain improper certificate validation vulnerability allowing unauthenticated remote code execution. Newly added to CISA KEV catalog.
F5 BIG-IP APM with OAuth profile configured contains heap-based buffer overflow enabling unauthenticated remote code execution. Added to CISA KEV catalog requiring federal agency remediation.
IBM FTM for RedHat OpenShift affected by numerous critical vulnerabilities including improper deserialization (CVE-2026-18163), symbolic link validation issues (CVE-2026-18169), and arbitrary code execution flaws (CVE-2026-18162). CVSS scores ranging from 8.0 to 9.9.
Security researcher Abdelhamid Naceri (Nightmare Eclipse) released a Microsoft Defender zero-day exploit that blocks antivirus updates, leaving systems vulnerable to threats. Microsoft has not yet issued a patch.
CISA ordered federal agencies to patch actively exploited Zyxel GS1900 series switch vulnerability by Thursday. Chinese-speaking threat actors exploiting this flaw alongside WordPress vulnerabilities have stolen data from 996 devices and over 18,500 database records from government targets.
Meta's Muse AI assistant contains a zero-day vulnerability exploitable via simple terminal command that can hijack the application and use its extensive permissions to spy on Mac users and control their connected accounts.
Security researchers developed attack technique allowing hackers with privileged access to register rogue external MFA providers that steal users' passwords during legitimate login attempts, bypassing multi-factor authentication controls.
Major breaches and claims including FBI compromise, EvilTokens disruption, and Chinese APT campaigns
ShinyHunters extortion gang claims breach of FBI systems using new Oracle PeopleSoft zero-day vulnerability, allegedly gaining access to internal services and stealing sensitive data on all FBI employees and job applicants including names, home addresses, and phone numbers. Also claims to have seized FBI job applicants' site.
Microsoft Digital Crimes Unit facilitated disruption of EvilTokens phishing-as-a-service platform after it compromised over 12,000 Microsoft 365 accounts across 10,000+ organizations. Platform used AI-assisted lures, automated infrastructure, and device code phishing. Microsoft seized 50 websites and disabled 150+ domains. Two UK arrests made following takedown.
Chinese-speaking threat actor actively exploiting vulnerabilities in Zyxel GS1900 Smart Managed Switches and WordPress to steal sensitive data from 996 devices and more than 18,500 records from backend databases, specifically targeting government entities.
Ahmed Hossam Eldin Elbadawy, 24-year-old Texas resident and early Scattered Spider member involved in The Com hacker subset, pleaded guilty to federal charges related to extortion attack spree from 2021 to 2023.
ANY.RUN researchers investigated CSuite phishing and remote-access operation combining credential theft, Microsoft 365 session hijacking, and abuse of legitimate management tools. Campaign shows 60% US focus with sophisticated targeting of organizations.
Michael 'Miki' Bar, 43-year-old CISO for Hamat Group, indicted for remotely accessing cameras, stealing passwords, and infiltrating 26 companies from his position of trust within three weeks of arrest by Israeli authorities.
AI-powered malware and supply chain attacks including ClosedQuorum autonomous malware and TanStack npm compromise
New Windows malware ClosedQuorum uses Google Gemini, DeepSeek, Qwen, and Mistral AI models to autonomously determine actions during post-compromise attack stages, representing significant evolution in AI-assisted malware capabilities.
CrowdSec cybersecurity firm suffered data breach where threat actors stole 170 private GitHub repositories using OAuth token stolen from former employee's computer through TanStack npm supply chain attack, demonstrating sophisticated supply chain compromise.
Multiple encrypted GuLoader samples and Formbook PowerShell stagers observed in active malware distribution campaign. URLs include obfuscated PS1 scripts hosted on compromised infrastructure at 185.29.10.35, 158.94.210.129, and surun.info domains.
Significant IoT botnet activity detected with multiple Mirai and Mozi malware download URLs targeting vulnerable devices. Activity spans IP ranges across Asia-Pacific region including China, Taiwan, and India with over 20 distinct distribution endpoints.
Threat actors distributing AgentTesla and RemcosRAT payloads hidden in image files using steganography techniques. Malicious PNGs and JPGs hosted on compromised legitimate sites including pub-ce02802067934e0eb072f69bf6427bf6.r2.dev and adcentral.com.mx.
30 newly disclosed ransomware victims including government agencies, healthcare providers, and critical infrastructure
Brazilian Ministry of Finance's Federal Revenue Service breached by emperador ransomware group. Threat actors claim thousands of documents containing personnel and customer data plus all user data on gov.br portal with passwords compromised. Critical government finance sector breach.
Asyad Group, Oman's global integrated logistics provider ranked 4th on Forbes' '10 Biggest Logistics Companies in MENA' list, breached by Spirals ransomware group. Critical infrastructure and supply chain impact expected.
Major healthcare provider Fresenius Medical Care breached by ShinyHunters group. Two-day deadline issued to prevent publication of sensitive patient and operational data. Updated September 23, 2026 with publication deadline September 25, 2026.
OnTrac, major US last-mile e-commerce delivery company serving 75% of US population (formed from LaserShip-OnTrac merger), breached by emperador ransomware group. Critical supply chain and logistics infrastructure affected.
Legis, 60+ year old Latin American legal and business information publisher serving six countries (Colombia, Venezuela, Argentina, Mexico, Peru, Chile), breached by Rhysida group. Databases (SQL), PST/OST files, and legal documents exposed.
Clark Hill PLC, full-service Detroit-headquartered law firm, breached by SilentRansomGroup. Legal services firm compromise exposes client data and privileged communications.
Cozen O'Connor, Philadelphia-based American full-service law firm founded 1970, breached by SilentRansomGroup. Legal services breach threatens client confidentiality across multiple practice areas.
HIT d.d., prominent Slovenia-based entertainment and gaming provider with 40+ years experience operating hotels, casinos, wellness centers across Slovenia, breached by Akira ransomware. 77GB corporate data to be uploaded.
Merrimack County government administration compromised by Booba Project ransomware. 3GB of government data stolen from county systems.
Washington County Maine government administration systems breached by Booba Project. 2GB stolen from county government infrastructure.
Elsevier Evolve, Sherpath, ClinicalPharmacology, and GSDD APIs hijacked in LAPSUS$ redirect campaign. Users and systems attempting to connect to medical education platforms redirected to extortion splash pages pointing to lapsus[.]ar[.]io and lapsus[.]bz domains.
Sweden's IMY regulator fined IT systems provider Miljödata $183,000 (SEK 1.8 million) for inadequate security leading to August 2025 breach affecting 2.2 million people. Significant GDPR enforcement action.
Canadian regulator opened investigation of IDScan for allegedly violating data privacy laws following data breach. Probe examines security practices and adequacy of victim notifications under Canada's federal private-sector privacy law.
Spokane Public Schools took systems offline Monday following overnight 'network security incident.' District investigating situation with some systems remaining offline as precautionary measure.
Notable security research including AI-assisted hacking, smart glasses vulnerabilities, and deception technologies
Security researchers demonstrated how Claude AI helped break into OpenAI systems in under 72 hours, exposing how rapidly AI is lowering the barrier for sophisticated hacking and accelerating attack timelines.
More than 80,000 AI relay servers helping users in China mask identities while accessing cutting-edge US large language models (LLMs), likely for model cloning purposes. Significant intellectual property and technology transfer concerns.
UK NCSC Chief Technology Officer Dave Chismon warned that AI imbalance means cyberattacks will likely grow as automated defenses struggle to keep pace with AI-enhanced offensive capabilities.
Security tests found that some inexpensive smart glasses can be hijacked over Bluetooth, exposing owners' photos, videos, and personal data to attackers within wireless range.
CISA published guidance on using deception technologies to help organizations with limited resources set traps for hackers. 'Deception by Design' guide provides old-school defensive techniques adapted for modern threats.
These briefings are compiled from publicly available threat-intelligence feeds, which may include CISA KEV, NIST NVD, the GitHub Advisory Database (OSV), abuse.ch, and Wordfence Intelligence. Data-breach and credential-leak items may include data from Have I Been Pwned and ransomware.live.
CVE® is a registered trademark of The MITRE Corporation. CVE Records are © The MITRE Corporation, reproduced under the CVE Program Terms of Use. WordPress vulnerability data is provided by Wordfence Intelligence, © Defiant, Inc. Breach data from Have I Been Pwned is licensed under CC BY 4.0.