The 24-hour period from September 23-24, 2026 saw intense cybersecurity activity across multiple threat vectors. Critical vulnerabilities dominated the landscape, including actively exploited zero-days in Check Point Security Gateway VPN (CVE-2026-85102), F5 BIG-IP APM, and Arista VeloCloud Orchestrator systems. WordPress sites face active exploitation of CVE-2026-87902 for remote code execution. The threat actor ShinyHunters breached the FBI's jobs website (FBIjobs.gov), potentially exposing sensitive data on FBI personnel including members of the bureau's secretive hacking unit. A sophisticated AI-driven Magecart campaign infected 100+ e-commerce sites, stealing over 600,000 credit card records using autonomous AI agents. Ransomware groups maintained aggressive operations with 30 new victims posted across leak sites, while the Ryuk ransomware operator received only a 24-month sentence despite $1.2M in extortions. New Android banking malware RemControl targets European and Canadian users through malvertising, and multiple supply chain vulnerabilities threaten GitLab, Kubernetes/GCP, and WordPress ecosystems.
Multiple critical vulnerabilities under active exploitation targeting enterprise VPN, network management, and web infrastructure
Pre-authentication remote code execution vulnerability in Check Point Security Gateway VPN certificate-handling functionality confirmed under active exploitation. Critical severity flaw allows unauthenticated attackers to compromise VPN gateways.
F5 released emergency patches for critical BIG-IP APM zero-day vulnerability being exploited for remote code execution. Application Proxy Module affected, allowing attackers to execute arbitrary code on enterprise load balancers.
Arista Networks patched actively exploited zero-day affecting VeloCloud Orchestrator On-Prem deployments. Vulnerability allows attackers to compromise SD-WAN management infrastructure.
Threat actors escalated from probing to actively exploiting CVE-2026-87902 in WordPress sites, writing malicious files to disk that execute shell commands when accessed. Remote code execution attacks observed in the wild.
IBM Concert 1.0.0-3.0.0 affected by multiple critical flaws including buffer overflow (CVE-2026-6730), use-after-free (CVE-2026-6928), and command injection (CVE-2026-6721) enabling RCE. CVSS scores up to 9.8.
InfraTrust report warns attackers increasingly target enterprise infrastructure management systems with critical vulnerabilities actively exploited before or shortly after vendor disclosure.
Multiple command injection and code execution vulnerabilities in IBM DataStage on Cloud Pak for Data 5.4.0.0, including CVE-2026-81537 (CVSS 8.8) allowing authenticated RCE via OS command injection.
Remote code execution vulnerability in Microsoft Office Outlook with CVSS 8.8, allowing attackers to execute arbitrary code through malicious files or messages.
Major data exposure incidents including FBI personnel data breach and massive ransomware victim disclosures
ShinyHunters breach of FBI jobs site exposed personal data of thousands of FBI officials including addresses, phone numbers, and spouses. Critically, the breach revealed members of FBI's secretive hacking team, potentially compromising operational security of the bureau's offensive cyber unit.
ImNotAVillain threat group advertising sale of Revolut data including 680 high-net-worth users. Financial services breach exposing sensitive customer information from major fintech platform.
ImNotAVillain group exposed Italy for data protection violations, publishing 85,000+ files totaling 150GB affecting top government departments, units and offices. Major government data breach.
Design platform Canva compromised through vendor's Salesforce instance by threat group 'The Seven Deadly Sins'. Canva listed on new leak site after refusing payment demands. Supply chain attack affects multiple vendor customers.
Krybit ransomware group compromised Air Tanzania (ATCL), the national flag carrier airline of Tanzania. Aviation sector breach potentially exposing passenger and operational data.
DragonForce ransomware compromised Winfashion Technologies, a B2B ERP platform for fashion industry. Preliminary analysis indicates extensive data exfiltration from fashion supply chain management system.
AI-driven Magecart campaign, new Android banking trojan, and evolving phishing techniques targeting credentials
Financially motivated threat actor deployed open-source AI agent frameworks to automate attacks on 100+ online retailers at scale, stealing over 600,000 credit card records. First observed use of autonomous AI agents for web skimming operations represents significant evolution in e-commerce threat landscape.
New Android malware-as-a-service platform RemControl distributed through malvertising campaigns impersonating TVTap IPTV app. Targets banking users in European countries and Canada with remote access trojan capabilities.
The third-party.com domain commonly used in developer documentation now serves fake Cloudflare verification pages tricking Windows users into executing malicious PowerShell commands. Supply chain risk from poisoned documentation examples.
Active RemcosRAT malware distribution observed via HTTP at 31.70.122.27 serving ACH.hta. Remote access trojan campaign targeting Windows systems.
Significant IoT botnet activity with 30+ malware download URLs identified distributing Mirai and Mozi variants. Targets include MIPS and ARM architectures for IoT device compromise.
Threat actors poisoning ChatGPT, Gemini, and Google AI Overview by seeding web with malicious links and optimized content. Large-scale AI manipulation for phishing and disinformation distribution.
Advanced evasion techniques including EDR bypass, process injection, and cloud service exploitation
Single Kubernetes YAML file can grant control over entire Google Cloud organization by exploiting Google Kubernetes Config Connector authority. Confused deputy problem allows limited-permission users to escalate privileges.
New process parameter-poisoning technique evades EDR by injecting code into process initialization structures without using Windows APIs that EDR tools monitor. Allows stealthy process injection bypassing endpoint defenses.
Incoming email addresses automatically assigned to GitLab users contain highly privileged access tokens exploitable by attackers for supply chain compromise.
Scammers exploit OAuth device code flow to trick users into approving authentication that signs attackers into victim accounts. Social engineering technique bypassing traditional phishing detection.
Turbo Intruder now supports HTTP/3 protocol, achieving over 100,000 requests per second over Wi-Fi with auto-tuning. Significantly increases velocity of web application attacks and fuzzing campaigns.
Ransomware operations, threat actor prosecutions, and ongoing cybercriminal campaigns
Armenian national Karen Vardanyan sentenced to only 24 months for role in Ryuk ransomware attacks that extorted $1.2 million from victims worldwide. Lenient sentence raises concerns about deterrence for ransomware operations.
ShinyHunters extortion group claims FBI jobs site breach was retaliation for bureau's warning about their tactics. Group stole sensitive data on FBI agents and job applicants, demanding report retraction.
Multiple ransomware groups (Qilin, Akira, Wallstreet, DragonForce, Spirals, Pear, IncRansom, Rhysida, ZaWoo) posted 30 new victims spanning healthcare, legal, manufacturing, agriculture, aviation, and government sectors. Indicates sustained high-tempo ransomware operations.
Latvian police arrested 23-year-old suspect for hacking at least two companies, stealing personal information and attempting extortion. Multiple attacks detected using similar methods starting February 2026.
Multiple WordPress plugin vulnerabilities including privilege escalation and authentication bypass
Laravel-Mediable 7.0.0-7.0.2 contains incomplete patch for previous CVE. Missing .pht extension from blocklist allows PHP execution via Apache. Critical severity CVSS 9.8.
Import and export users plugin for WordPress vulnerable to privilege escalation in versions up to 2.4.17. Export/re-import workflow allows attackers to gain elevated privileges through CSV manipulation with NUL bytes. CVSS 8.8.
EthPress Web3 Login plugin vulnerable to authentication bypass in all versions up to 2.3.5. Missing return statement in signature verification allows attackers to bypass Web3 authentication. CVSS 8.1.
International cybersecurity policy developments and government initiatives
EU auditors found €1.4 billion cyberattack early-warning system still not fully operational 20 months after deployment. Nobody verified if the continent-wide defense infrastructure actually works.
Ofcom investigating Pornhub parent company for alleged age verification failings. New age assurance process relies on Apple signals suggesting users completed age checks, raising privacy and effectiveness concerns.
U.S. intelligence officials found no evidence any foreign adversary successfully interfered in 2024 presidential election according to classified assessment. Conclusion follows concerns about Russian, Chinese, and Iranian influence operations.
UK Prime Minister Andy Burnham announced creation of new national center to detect, attribute and disrupt hostile state disinformation at UN General Assembly. Targets Russian and other state-sponsored information operations.
OpenAI extending Daybreak program access to Ukrainian government to support cyber defense of civilian infrastructure. AI-powered defensive capabilities provided for nation under sustained cyberattack.
Critical vulnerabilities in open source libraries and development tools
Critical vulnerability in @bytebase/dbhub allows DNS rebinding attacks enabling unauthenticated browser-origin SQL execution. CVSS 9.3 affects HTTP transport layer.
Critical CVSS 10.0 vulnerability in decepticon-core allows role-boundary forgery via ChatML special-token literals in web crawl output. Attackers can manipulate LLM context through crafted tokens.
Multiple high-severity flaws in Klever blockchain (prior to 1.7.20): unauthenticated WebSocket endpoints lack rate limiting and message size bounds, enabling resource exhaustion attacks. CVSS 7.5-8.6.
Language Servers for AWS vulnerable to arbitrary file write (CVE-2026-12958) and code execution (CVE-2026-12957). Both rated CVSS 8.5, affecting development environment security.
Malformed container images can trick podman run into leaking host environment variables into containers (CVE-2026-57231). CVSS 7.5 supply chain risk in container runtime.
These briefings are compiled from publicly available threat-intelligence feeds, which may include CISA KEV, NIST NVD, the GitHub Advisory Database (OSV), abuse.ch, and Wordfence Intelligence. Data-breach and credential-leak items may include data from Have I Been Pwned and ransomware.live.
CVE® is a registered trademark of The MITRE Corporation. CVE Records are © The MITRE Corporation, reproduced under the CVE Program Terms of Use. WordPress vulnerability data is provided by Wordfence Intelligence, © Defiant, Inc. Breach data from Have I Been Pwned is licensed under CC BY 4.0.