Cyber Watch

Tue 06 Oct 2026
Items, last 7d
326
35 today · 36 sources
New KEVs, 7d
4
added to CISA's KEV catalog · 0 with known ransomware use
KEV due ≤7d
1
CISA remediation deadlines by 10-13 · 0 ransomware
AOR leak-site victims, 7d
66
of 151 worldwide · PACOM AOR countries incl. US
Critical CVEs, 7d
34
NVD CVSS ≥ 9.0 published

This week's brief Issue 2026-W40 · 7 curated items

Edge devices drove the week: Citrix NetScaler intrusions began three weeks before the patch, and Cisco SD-WAN Manager and FortiMail joined KEV. Needs attention: the DMDC breach exposed SSNs and service records of 2.76 million people.

Watch list · next 7 days
  • KEV due 5 Oct: chained Zammad CVE-2026-102489 and -102490.
  • SDA PWSA transport launch from Vandenberg, 5 Oct.
  • Further Mandiant reporting on NetScaler attribution.
  • Fake iPhone Duo preorder lures before 16 Oct.

Last 7 days by lane

Operations 194Force Protection 85Space & Cyber Professionals 47

Rising terms last 7d vs prior

ransomware176 (+52.7)AI81 (+23.8)China41 (+21.8)energy30 (+19)phishing27 (+14.5)healthcare28 (+9.1)Microsoft30 (+8.4)supply chain14 (+7)

Fading

KEV13 (-11.7)CISA23 (-11.1)Australia8 (-3.9)VPN0 (-3.3)crypto2 (-2.9)

Threat actors in the news 7d

ShinyHunters
11
TA419
6
Warlock / Storm-2603
6
Scattered Spider
5
Qilin
3

APT spotlight rotates weekly

UAT-11587 China-nexus (per Cisco Talos)
Overlaps Jewelbug (Symantec)
AI-curated
Why now
Cisco Talos named UAT-11587 on 30 Sep after ten months of espionage in Asia.
Notable TTPs
  • Tailored spear-phishing decoys
  • Five-stage chain staged on Cloudflare
  • Rust backdoor Antino with Outlook/OneDrive C2
Recent activity
  • Talos: about 350 endpoints affected, Sep 2025 to Jul 2026 (Cisco Talos, 30 Sep 2026)
  • Overlaps with Symantec's Jewelbug activity, per Talos (Cisco Talos, 30 Sep 2026)
  • Philippines and Taiwan waves, Mar to Jun 2026 (The Hacker News, 2 Oct 2026)
Countermeasures
  • Alert on Graph and OneDrive calls from non-browser processes
  • Block HTA execution on endpoints
  • Share Talos indicators with partner liaisons
PACOM relevance
Victims include Philippine and Taiwanese government and defense organizations.

Linked reporting

All items for this actor →

Patch clock CISA KEV entries with deadlines still ahead · soonest first

DueCVEVendor / productAdded
10-07CVE-2026-88779Citrix NetScaler10-03due ≤7d

1 open, 36 past due. Due dates are CISA’s BOD remediation deadlines for federal agencies — a useful patch clock for everyone else.

Critical CVEs to get ahead of 7d · vendors already in KEV

PublishedCVECVSSVendorSummary
09-30CVE-2026-765049.8CiscoA vulnerability in the API session-based authentication management of Cisco Catalyst SD-WA
10-01CVE-2026-976379.8WordPressThe JSON API Auth plugin for WordPress is vulnerable to Authentication Bypass via Cached S
10-01CVE-2026-196609.8WordPressThe Divi Membership plugin for WordPress is vulnerable to Authentication Bypass in all ver

9 of 34 CRITICAL CVEs published in 7d (NVD) name a vendor with an exploited bug in KEV this window; vendor matched on the NVD description.

Ransomware in the AOR leak-site claims, 30d

PostedVictimCtryGroupSector
10-05part02.simplexengg.inINEclipseTechnology
10-05M** A******* G********** O****USnetrunnerNot Found
10-05Nelson Mullins Riley & ScarborUSSilentRansomGrouProfessional Servi
10-05Sheppard, Mullin, Richter & HaUSSilentRansomGrouProfessional Servi
10-05Turn5USGlobal Secret GrOther
10-05grundens.comUSsafepayRetail & E-Commerc
10-05Asia Era OneMYqilinNot Found
10-05Philander Smith UniversityUSEndZoneEducation

Groups hitting the AOR 30d

Storm
24
qilin
21
thegentlemen
17
incransom
13
metaencryptor
12

219 of 516 victims in 30d are in AOR countries (US included). Leak-site claims via ransomware.live — not confirmed incidents.

Items one lane per item · tags: COCOM, category, actor, country

Operations 0 items Threats to networks, missions, and infrastructure the command depends on: exploited vulns, intrusions, APT campaigns, ICS/OT, SATCOM/PNT, telecom.

2026-10-06 · SecurityWeek · score 2.5
An alleged leader of Tren de Aragua’s ATM jackpotting activities, Canelon Aguirre was on the FBI’s top 10 most wanted list since March 2026.
NORTHCOMMalware & toolingUnited States
2026-10-06 · SecurityWeek · score 2.5
Since August 2023, attackers have published eight malicious packages as part of the MALFEX supply chain campaign.
Supply chainMalware & tooling
2026-10-06 · The Record (Recorded Future) · score 2.5
Aguirre was added to the FBI’s “Top 10 Most Wanted Fugitives” list in March, becoming the first cybercriminal added to the list.
NORTHCOMMalware & toolingUnited States
2026-10-06 · The Hacker News · score 3
In 2024, MCP (Model Context Protocol) set out to become the USB-C of AI: one standard for connecting models, agents, and IDEs to tools and data. The protocol delivered. Thousands of developers built servers, and enterprises plugged them into agent workflows. The ecosystem around it fell short. Earlier this year, our team at OX Security, traced critical vulnerabilities in Anthropic's MCP
AI & cyberVulns & exploits
2026-10-06 · Canadian Centre for Cyber Security · score 3.25
Vulns & exploits
2026-10-06 · DefenseScoop · score 3.5
Billions of dollars are slated to be invested in the Arsenal-2 facility in Baltimore County, Maryland.
PACOMNORTHCOMSupply chainChinaUnited States
2026-10-06 · The Record (Recorded Future) · score 4.25
CERT-UA found fake Cloudflare verification pages that led visitors into a now-familiar ClickFix trap. This time the goal was to infect machines with an infostealer.
EUCOMMalware & toolingSocial engineeringUkraine
2026-10-06 · BleepingComputer · score 4.25
RMM platforms give MSPs privileged access across customer environments, making their security controls critical to limiting risk. Acronis outlines eight controls MSPs should test when evaluating RMM software, from patching and privileged access to recovery and tenant isolation. [...]
Supply chainVulns & exploitsCloud & identity
2026-10-06 · Canadian Centre for Cyber Security · score 4.75
Apps & devicesVulns & exploits
2026-10-06 · SecurityWeek · score 6
The FBI has removed an Accenture contractor over a data breach that exposed personal information of thousands of bureau employees.
NORTHCOMBreach & leaked dataVulns & exploitsSupply chainShinyHuntersUnited States
2026-10-06 · Palo Alto Unit 42 · score 6.25
Analysis of Blinder Tunnel, an Iran-nexus campaign using fake Dubai Airports recruitment lures and GitHub C2 malware to target critical infrastructure.
CENTCOMNORTHCOMMalware & toolingSocial engineeringCritical infrastructureIran
2026-10-06 · CISA Cybersecurity Advisories · score 6.25
View CSAF Summary Hitachi Energy is aware of unauthenticated servlet access vulnerabilities that affect Asset Suite product versions listed in this document. These vulnerabilities can be exploited to potentially cause confidentiality, integrity and availability impact on the product. Please refer to the Recommended Immediate Actions for information about the mitigation/remediation. The following versions of Hitachi Energy Asset Suite are affected: Asset Suite vers:Asset_Suite/<=9.9.0 (CVE-2026-7395, CVE-2026-11796) CVSS Vendor Equipment v3 8.1 Hitachi Energy Asset Suite 1 Vulnerability Missing Authentication for Critical Function Background Critical Infrastructure Sectors: Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Switzerland Vulnerabilities Expand All + CVE-2026-7395 Asset Suite allows unauthenticated users to access HTTPPublishAdapterTestServlet that can be used for configuration file upload, leading to information disclosure and integrity compromise. The HTTPPublishAdapterTestServlet is specifically meant for testing purposes to be used in a non-production environment. Read More 1 Affected Product Asset Suite versions 9.9.0 and prior Product…
NORTHCOMVulns & exploitsCritical infrastructureSupply chain
2026-10-06 · CISA Cybersecurity Advisories · score 6.25
View CSAF Summary Hitachi Energy is aware of RCE (Remote Code Execution) vulnerability in Apache ActiveMQ component of SOI product versions listed in this document. These vulnerabilities can be exploited to carry out various attacks affecting confidentiality, integrity, and availability of the product. Please refer to the Recommended Immediate Actions for information about the mitigation/remediation. The following versions of Hitachi Energy SOI are affected: SOI vers:SOI/>=2.0.0|<=2.2.0 (CVE-2026-34197) CVSS Vendor Equipment v3 8.8 Hitachi Energy SOI 1 Vulnerability Improper Control of Generation of Code ('Code Injection') Background Critical Infrastructure Sectors: Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Switzerland Vulnerabilities CVE-2026-34197 Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ used in SOI product. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. The default Jolokia access policy permits exec operations on all ActiveMQ MBeans (org.apache.activemq:*), including…
NORTHCOMVulns & exploitsCritical infrastructureSupply chain
2026-10-06 · CISA Cybersecurity Advisories · score 6.25
View CSAF Summary Hitachi Energy is publishing this cybersecurity advisory in response to the security findings reported by Dragos affecting end-of-life RTU500 CMU firmware version 9.x. The reported findings are associated with legacy RTU500 firmware versions that were developed according to the cybersecurity requirements, threat landscape, and industry practices that existed at the time of their release. As cybersecurity threats and security expectations have evolved, these end-of-life versions no longer incorporate many of the security controls and hardening measures that are standard in modern industrial control systems. Over successive RTU500 releases, Hitachi Energy has continuously enhanced the security of the product through the introduction of additional security features, protocol hardening, stronger authentication and access controls, encrypted communications, and other security-by-design improvements. While the findings reported by Dragos do not affect currently supported RTU500 CMU firmware versions, there is a likelihood that the end-of-life versions 11.x and prior are affected by these vulnerabilities. Since the end-of-life versions are no longer maintained with…
ICS / OTVulns & exploitsSupply chain
2026-10-06 · CISA Cybersecurity Advisories · score 6.5
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to gain full unauthorized access to the device. The following versions of Johnson Controls EasyIO FG are affected: EasyIO FG firmware <=2.0b52 (CVE-2026-27872, CVE-2026-27873) CVSS Vendor Equipment v3 7.7 Johnson Controls EasyIO FG firmware 2 Vulnerabilities Use of Hard-coded Credentials, Improper Privilege Management Background Critical Infrastructure Sectors: Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Ireland Vulnerabilities Expand All + CVE-2026-27872 A vulnerability exists in EasyIO FG relating to an attacker gaining unauthorized access to the system through hard-coded credentials and improper privilege management, potentially resulting in full device compromise. Successful exploitation could result in technical or operational impact. Read More 1 Affected Product Johnson Controls EasyIO FG firmware: <=2.0b52 Product Status: known_affected Remediations Mitigation Johnson Controls has determined that the EasyIO FG Series has reached End-of-Life (EOL)…
Vulns & exploitsSupply chainPolicy & guidance
2026-10-06 · Microsoft Security / MSTIC · score 6.5
Learn how CISOs can mitigate cybersecurity risks and increase resilience in the age of AI-powered vulnerability management.
NORTHCOMVulns & exploitsStrategy & organizationAI & cyber
2026-10-06 · Nikkei Asia · via TJFSCC Daily · score 6.5
PACOMVulns & exploitsChinaJapanvia TJFSCC Daily
2026-10-06 · The Register — security · score 6.75
Run the CLI in autopilot mode and take your chances
NORTHCOMAI & cyberVulns & exploitsApps & devices
2026-10-06 · CISA Cybersecurity Advisories · score 7
View CSAF Summary Hitachi Energy is aware of open-source software vulnerabilities that affect REB500 product versions listed in this document. These vulnerabilities can be exploited to carry out Denial of Service (DoS) attack on the product. Please refer to the Recommended Immediate Actions for information about the mitigation/remediation. The following versions of Hitachi Energy REB500 are affected: REB500 vers:REB500/<=8.3.3.1 (CVE-2024-8176, CVE-2025-59375) CVSS Vendor Equipment v3 6.5 Hitachi Energy REB500 2 Vulnerabilities Uncontrolled Recursion, Allocation of Resources Without Limits or Throttling Background Critical Infrastructure Sectors: Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Switzerland Vulnerabilities Expand All + CVE-2024-8176 A stack overflow vulnerability exists in the libexpat library used by the IEC61850 functionality supported by REB500 product. An authenticated malicious user with local access could use a crafted IEC 61850 message to exploit the vulnerability in the libexpat library. This issue could lead to denial of service (DoS) or, in some cases, exploitable memory corruption, depending on the environment and library usage.…
NORTHCOMVulns & exploitsSupply chainICS / OT
2026-10-06 · Nextgov/FCW — cybersecurity · score 7.5
The bureau’s cyber chief blamed a contractor’s failure to apply an available fix for an intrusion that may have exposed sensitive employee information.
NORTHCOMVulns & exploitsBreach & leaked dataSupply chainShinyHuntersUnited States
2026-10-06 · The Japan Times · via TJFSCC Daily · score 7.5
Qilin is believed to have carried out ransomware attacks against companies worldwide, causing major damage through data encryption.
PACOMEUCOMRansomwareStandards & complianceQilinJapanvia TJFSCC Daily
2026-10-06 · The Neuron · via AI feed · score 8
Welcome, humans. The U.S. Army spent the past few years pushing drones, AI, and autonomous systems into its units at the same time. This week, acting chief of staff Gen. Christopher LaNeve said the Army [needs to narrow its modernization push](https://www.foxnews.com/politics/emerging-tech-army-leaders-warning-troops-cant-ai-way-victory-battlefield?utm_source=www.theneurondaily.com&utm_medium=newsletter&utm_campaign=openai-will-watermark-chatgpt-text), because too much was changing at the same time. He also said no brigade commander can AI their way to being the best at the job. The fix is a…
EUCOMNORTHCOMAI & cyberStandards & complianceScattered SpiderUnited Statesvia AI feed
2026-10-06 · CISA Cybersecurity Advisories · score 8.5
View CSAF Summary Successful exploitation of this vulnerability could crash the device being accessed; a buffer overflow condition may allow remote code execution. The following versions of Savannah lwIP SMTP client are affected: lwIP SMTP client 2.2.1 (CVE-2026-15340) CVSS Vendor Equipment v3 9.8 Savannah lwIP SMTP client 1 Vulnerability Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') Background Critical Infrastructure Sectors: Energy, Water and Wastewater Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: Sweden Vulnerabilities CVE-2026-15340 lwIP SMTP client does not check the size of inputs, potentially allowing a buffer overflow. Read More 1 Affected Product Savannah lwIP SMTP client: 2.2.1 Product Status: known_affected Remediations Mitigation xchglabs reports that the vulnerability was fixed and released in the following patch: patch_125_smtp_txbuf.diff . This is available as available as git commit (614420f82c8729d070e01464c0dddb3c9525c772) Additional Metrics Relevant CWE: CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') CVSS Version Base Score Base Severity Vector String 3.1 9.8 CRITICAL…
EUCOMVulns & exploitsCritical infrastructureICS / OT
2026-10-06 · CyberScoop · score 8.75
Government auditors say federal agencies haven’t met mandated security steps for operational technology, which hackers targeted in water sector attacks this summer.
NORTHCOMCYBERCOMPolicy & guidanceCritical infrastructureICS / OTUnited States
2026-10-05 · BleepingComputer · score 2.5
The U.S. Department of Justice has announced the arrest of the alleged developer of Ploutus malware, used to steal millions of dollars in ATM jackpotting attacks across the United States. [...]
NORTHCOMMalware & toolingUnited States
2026-10-05 · The Record (Recorded Future) · score 2.5
A ransomware attack that affected the University of Illinois Chicago (UIC) College of Medicine resulted in the theft of some information from its servers.
Ransomware
2026-10-05 · SecurityWeek · score 3
CVE-2026-61500 allows attackers to recover the session-cookie signing key and gain administrative access and RCE.
Vulns & exploitsCloud & identity
2026-10-05 · The Hacker News · score 3.25
Threat actors have been observed attempting to exploit a now-patched critical security flaw impacting the Realtek Jungle software development kit (SDK) to deploy a botnet malware called Cling. "Cling is notable not because it introduces a new propagation technique, but because it repurposes ordinary STUN behavior into a practical command-and-control channel," Nozomi Networks said in a report
Malware & toolingVulns & exploits
2026-10-05 · SecurityWeek · score 3.25
Google has temporarily stopped accepting product vulnerability reports through its Open Source Software Vulnerability Reward Program (OSS VRP).
Supply chainVulns & exploits
2026-10-05 · Canadian Centre for Cyber Security · score 3.25
Vulns & exploits
2026-10-05 · The Hacker News · score 3.25
Google has stopped accepting product vulnerability reports through its bug bounty program for its open-source software. The change, in effect since October 1, means researchers can no longer submit security flaws in the code of projects such as Go, Angular, and Protocol Buffers there for a reward. Reports about supply chain compromises are still accepted, and reports filed before October 1 are
Supply chainVulns & exploits
2026-10-05 · The Hacker News · score 3.25
A critical flaw in 8 Atlassian Data Center products, which customers host themselves, allows an attacker with no login access to read specific files in each product's web application root directory. The attacker must already know a file's exact name and path and cannot list what the directory holds. Atlassian disclosed the flaw, CVE-2026-21589, on October 5, rated it 9.3 out of 10, and
Vulns & exploitsMalware & tooling
2026-10-05 · Canadian Centre for Cyber Security · score 3.5
NORTHCOMVulns & exploits
2026-10-05 · BleepingComputer · score 3.75
Hackers are actively scanning for a Rejetto HFS weak signing key vulnerability, tracked as CVE-2026-61500, that allows session forgery, account takeover, and remote code execution (RCE). [...]
Vulns & exploitsScams & fraud
2026-10-05 · Dark Reading · score 3.75
The Linux backdoor exploits 24 known flaws to compromise IoT devices and uses legitimate public STUN servers to obscure communications.
NORTHCOMApps & devicesMalware & tooling
2026-10-05 · Canadian Centre for Cyber Security · score 4.25
Vulns & exploitsCloud & identity
2026-10-05 · Politico Europe · via TJFSCC Daily · score 4.25
One of the greatest potential intelligence breaches in post-Cold War German history comes at a particularly sensitive time for the country’s scandal-plagued foreign intelligence agency.
APT & espionageBreach & leaked datavia TJFSCC Daily
2026-10-05 · The Hacker News · score 4.5
A blank field. A public repo. One reply to an email. A box left exposed. None of this sounds dramatic, which is partly the problem. This week’s threats keep finding leverage in small things that were easy to overlook. There are actively exploited bugs in the mix, cleaner intrusion paths, smarter automation, and a long patch list waiting behind them. Some attacks are getting more capable. Others
Vulns & exploitsRansomwareBreach & leaked data
2026-10-05 · Canadian Centre for Cyber Security · score 4.5
Vulns & exploitsCloud & identity
2026-10-05 · The Hacker News · score 4.5
Microsoft has released out-of-band security updates to address a high-severity flaw in Microsoft Exchange Server that could allow an attacker to escalate privileges under certain conditions. The vulnerability, tracked as CVE-2026-96940, is rated 8.8 on the CVSS scoring system. "Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a
Vulns & exploitsMalware & toolingCloud & identity
2026-10-05 · CyberScoop · score 4.5
The vendor was much quicker and consistent in its response to the latest defect, and researchers consider the impact relatively low compared to the previous pair of zero-days.
Vulns & exploitsSupply chainHacktivism & DDoS
2026-10-05 · Canadian Centre for Cyber Security · score 4.75
Vulns & exploitsApps & devices
2026-10-05 · Canadian Centre for Cyber Security · score 5.5
NORTHCOMVulns & exploitsStandards & complianceUnited States
2026-10-05 · The Record (Recorded Future) · score 5.5
Russian cybersecurity researchers attributed a quiet two-year espionage campaign to the Belarusian Cyber Partisans, a group better known for public attacks against governments and infrastructure.
EUCOMHacktivism & DDoSAPT & espionageRussia
2026-10-05 · DefenseScoop · score 5.5
Microsoft Copilot illustrates how AI agents, built within commonly used, pre-approved and secure defense environments, can boost employee productivity.
NORTHCOMAI & cyberCloud & identitySupply chain
2026-10-05 · Inside Defense · via TJFSCC Daily · score 5.5
The Army has awarded Anduril $162.8 million under a five-year contract to build out its Next Generation Command and Control common data layer baseline in the Pacific as the service scales NGC2 to I Corps. The value awarded is part of an initial base period, the company said in an announcement , with options included that could bring its value up to $1.8 billion over the five-year period. The Army validated NGC2 at the division level during Project Convergence Capstone 6 in the desert at the National Training Center, Ft Irwin, CA, this past July. Before that, it chose Anduril’s Lattice software to take the lead on NGC2’s common data layer baseline, meaning Anduril’s software connects “applications, data, [artificial intelligence] models, sensors, vehicles and other battlefield systems within NGC2,” according to the company. The service adds in its announcement that a single company alone should be in charge of the Army’s C2 stack and argues a common data layer affords the Army the ability to patch in new systems seamlessly. The five-year award is focused on fielding NGC2 to the corps in the Pacific; I Corps oversees four divisions that are thousands of miles from one another and…
PACOMVulns & exploitsvia TJFSCC Daily
2026-10-05 · Inside Defense · via TJFSCC Daily · score 5.5
The Army has awarded Anduril $162.8 million under a five-year contract to build out its Next Generation Command and Control common data layer baseline in the Pacific as the service scales NGC2 to I Corps. The value awarded is part of an initial base period, the company said in an announcement , with options included that could bring its value up to $1.8 billion over the five-year period. The Army validated NGC2 at the division level during Project Convergence Capstone 6 in the desert at the National Training Center, Ft Irwin, CA, this past July. Before that, it chose Anduril’s Lattice software to take the lead on NGC2’s common data layer baseline, meaning Anduril’s software connects “applications, data, [artificial intelligence] models, sensors, vehicles and other battlefield systems within NGC2,” according to the company. The service adds in its announcement that a single company alone should be in charge of the Army’s C2 stack and argues a common data layer affords the Army the ability to patch in new systems seamlessly. The five-year award is focused on fielding NGC2 to the corps in the Pacific; I Corps oversees four divisions that are thousands of miles from one another and…
PACOMVulns & exploitsvia TJFSCC Daily
2026-10-05 · The Record (Recorded Future) · score 5.75
Citrix confirmed late on Friday that it was “tracking a newly observed issue” related to some customer-managed NetScaler deployments but claimed the problem was not connected to vulnerabilities reported last week that also caused alarm among cybersecurity experts.
PACOMNORTHCOMVulns & exploitsAustralia
2026-10-05 · Industrial Cyber · score 6
Health Information Sharing and Analysis Center (Health-ISAC) announced that Vasileios Mingos, Health-ISAC’s European Operations Director, has been elected...
EUCOMNORTHCOMCritical infrastructureVulns & exploits
2026-10-05 · The Hacker News · score 6.25
The U.S. Federal Bureau of Investigation (FBI) has removed an Accenture contractor for their alleged role in a ShinyHunters-breach that led to the theft of personal details of thousands of bureau employees. That's according to a report from Reuters, citing two sources familiar with the matter. "To date, our review has determined that the incident occurred as the result of a security failure ​
NORTHCOMVulns & exploitsBreach & leaked dataSupply chainShinyHuntersUnited States
2026-10-05 · Malwarebytes Labs · score 7
Google has frozen its OSS VRP product vulnerability submissions to stop the flood of AI generated vulnerability reports.
SPACECOMSupply chainVulns & exploitsAI & cyber
2026-10-05 · The Straits Times (Asia) · via TJFSCC Daily · score 7
The zoo has singled out shoebills, or hashibiroko, as its next stars.
PACOMAPT & espionageChinaJapanvia TJFSCC Daily
2026-10-05 · The Register — security · score 7.25
Tells users ‘action required’ – but maybe don’t make that action a Jira ticket, because it has this bug
PACOMVulns & exploitsCloud & identityMalware & toolingAustralia
2026-10-05 · The Register — security · score 7.75
Another few bite the dust
NORTHCOMEUCOMVulns & exploitsRansomwareBreach & leaked dataShinyHuntersUnited StatesUK
2026-10-05 · Infosecurity Magazine · score 8.75
Rapid7 has uncovered new BPFDoor, BPF Rekoobe and AVERAT malware variants targeting telecom and network-edge appliances in South Korea and Taiwan
PACOMMalware & toolingTelecom & cablesROKTaiwan
2026-10-05 · Check Point Research · score 9
For the latest discoveries in cyber research for the week of 5th October, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Arizona’s state court system has suffered a phishing-led cyberattack after an employee clicked a malicious link. Attackers copied backup files containing protective-order records and more than 150,000 Foster Care Review Board reports […]
NORTHCOMAFRICOMVulns & exploitsAI & cyberBreach & leaked dataCanadaJapan
2026-10-05 · Industrial Cyber · score 9.25
Nozomi Networks Labs has identified a botnet dubbed Cling that exploits internet-exposed IoT and networking devices and disguises...
NORTHCOMPACOMVulns & exploitsMalware & toolingApps & devicesROKUnited States
2026-10-05 · The Diplomat · via TJFSCC Daily · score 9.25
The U.S. has benefited from hard-earned lessons in the fight against transnational online scams. It’s time to apply them to address China’s sophisticated and relentless cyber spying.
PACOMNORTHCOMAPT & espionageScams & fraudChinaUnited Statesvia TJFSCC Daily
2026-10-05 · Dark Reading · score 10.75
An emerging threat group known as TA419 established seemingly legitimate professional relationships with AI policy experts working for US think tanks, universities, and legal organizations.
PACOMNORTHCOMAPT & espionageSocial engineeringAI & cyberTA419China
2026-10-05 · CyberScoop · score 11.5
Here’s what it would take: stronger defenses for large utilities, hands-on help for smaller systems and federal support to make both happen.
NORTHCOMPACOMCritical infrastructureVulns & exploitsPolicy & guidanceUnited StatesIran
2026-10-05 · Nextgov/FCW — cybersecurity · score 12.5
Unauthorized users accessed sensitive records for roughly nine months before discovery, exposing another government personnel data fiasco as the FBI confronts its own breach incident.
NORTHCOMPACOMBreach & leaked dataVulns & exploitsAPT & espionageShinyHuntersUnited StatesChina
2026-10-05 · Industrial Cyber · score 13.5
New analysis from Centrii identified that cyber risk in the energy sector is increasingly becoming a financial and...
EUCOMNORTHCOMSupply chainAPT & espionageBreach & leaked dataVolt TyphoonChinaRussia
2026-10-04 · BleepingComputer · score 3.25
Citrix has released emergency updates for a new NetScaler denial-of-service vulnerability tracked as CVE-2026-88779 that has been exploited in zero-day attacks, with researchers investigating whether it can also be exploited for remote code execution. [...]
Vulns & exploitsHacktivism & DDoS
2026-10-04 · The Hacker News · score 4
A critical security flaw impacting Rejetto HTTP File Server (HFS) is witnessing active exploitation attempts, according to VulnCheck. The vulnerability in question is CVE-2026-61500 (CVSS score: 9.3), a case of session forgery stemming from the use of a weak pseudo-random number generator (PRNG) that can lead to a predictable key, which an attacker can then use to gain unauthorized access and
Vulns & exploitsPolicy & guidance
2026-10-04 · BleepingComputer · score 4.75
Google has now suspended submissions to its Open Source Software Vulnerability Rewards Program (OSS VRP) after being flooded by AI-generated reports. [...]
Supply chainVulns & exploitsSocial engineering
2026-10-04 · Industrial Cyber · score 7
The McCrary Institute for Cyber & Critical Infrastructure Security warned that artificial intelligence is accelerating cyber threats against...
NORTHCOMAI & cyberCritical infrastructureICS / OT
2026-10-04 · CISA Cybersecurity Advisories · score 7.5
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-88779 Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. While BOD 26-04 applies only to FCEB agencies, CISA encourages all…
NORTHCOMVulns & exploitsPolicy & guidanceBreach & leaked dataUnited States
2026-10-04 · The Japan Times · via TJFSCC Daily · score 8
The government will develop methods to detect cyberattack threats and share them with utilities and telecommunications companies.
PACOMCritical infrastructureTelecom & cablesJapanvia TJFSCC Daily
2026-10-03 · Politico Europe · via TJFSCC Daily · score 4.75
Mehr als die Hälfte der jungen Wähler entscheidet sich bei jüngsten Landtagswahlen für Parteien, die der Ukraine-Unterstützung kritisch gegenüberstehen. Der Grund dafür liegt nicht nur in klassischen Debatten, sondern auf Plattformen wie TikTok, Instagram und X. Dort tobt längst ein massiver Informationskrieg, in dem ausländische Akteure und Algorithmen um die Deutungshoheit kämpfen. Marcel Bohnert, Oberstleutnant […]
EUCOMVulns & exploitsApps & devicesUkrainevia TJFSCC Daily
2026-10-03 · The Hacker News · score 7
The U.K.'s domestic intelligence and security agency has warned that more than 100 academics have helped China boost its intelligence gathering efforts on behalf of Beijing's state security service. In a "Security Service Espionage Alert" issued on September 30, 2026, MI5 said the "primary purpose of the China General Technology Research Institute (CGTRI) 中国通用技术研究院 is to fund research that
PACOMAPT & espionageChina
2026-10-03 · The Register — security · score 8.5
Exploitation attempts came from China-hosted IP, VulnCheck researcher says
PACOMNORTHCOMVulns & exploitsSupply chainChinaJapan
2026-10-03 · South China Morning Post (China) · via TJFSCC Daily · score 8.5
From online-gambling rings in eSwatini to SIM swapping in Kenya and cybercrime networks in Zambia, a wave of cross-border fraud is drawing African governments and China into closer security cooperation. China hosted East African security ministers and police chiefs in Lianyungang, Jiangsu province, on September 10 for talks on terrorism, kidnapping, online fraud and other cross-border threats. China’s public security minister, Wang Xiaohong, said Beijing would strengthen law-enforcement...
AFRICOMPACOMScams & fraudTelecom & cablesChinavia TJFSCC Daily
2026-10-03 · The Hacker News · score 9.5
The suspected China-linked threat actor known as Warlock is still continuing to weaponize Microsoft SharePoint vulnerabilities, likely both old and new, in attacks targeting organizations in Portuguese- and Spanish-speaking countries. The activity, observed by the Symantec and Carbon Black Threat Hunter Team, has hit critical infrastructure, government, and education organizations. "In the
PACOMRansomwareCloud & identityVulns & exploitsWarlock / Storm-2603China
2026-10-03 · CISA Known Exploited Vulnerabilities · score 10.25
Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability. Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway) contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for a denial of service. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Due 2026-10-07.
NORTHCOMVulns & exploitsPolicy & guidanceBreach & leaked dataUnited StatesKEV
2026-10-02 · Dark Reading · score 2.5
One company told customers to power down its data-protection platform during a nine-hour window, while the other remained mum on reported attacks prior to releasing a patch for its product.
Vulns & exploits
2026-10-02 · Canadian Centre for Cyber Security · score 3
Vulns & exploits
2026-10-02 · Canadian Centre for Cyber Security · score 3
Vulns & exploits
2026-10-02 · Canadian Centre for Cyber Security · score 3
Vulns & exploits
2026-10-02 · Canadian Centre for Cyber Security · score 3
Vulns & exploits
2026-10-02 · Canadian Centre for Cyber Security · score 3
Vulns & exploits
2026-10-02 · The Hacker News · score 3
A critical flaw in GitLab's AI Gateway could let a logged-in user with Duo Agent Platform access run commands on the gateway under certain conditions, GitLab said in an advisory. The gateway is the service that connects a GitLab instance to AI models, and only organizations that host their own gateway need to act. The flaw is fixed in gateway versions 19.2.4, 19.3.2, and 19.4.1. The flaw
Vulns & exploitsAI & cyber
2026-10-02 · The Record (Recorded Future) · score 3.25
Government services were temporarily disrupted by ransomware in Vicksburg, Mississippi. Mayor Willis Thompson said the FBI and other authorities are investigating.
NORTHCOMRansomwareUnited States
2026-10-02 · Canadian Centre for Cyber Security · score 3.25
Vulns & exploits
2026-10-02 · Dark Reading · score 4.5
Patch middleware vulnerabilities now to avoid hardware-based MFA exploits in ultra-sensitive environments.
Vulns & exploitsOPSEC & personal security
2026-10-02 · The Hacker News · score 4.75
The quarterly board meeting is two weeks out. The security team is pulling exports from the identity provider, the cloud posture tool, the vulnerability scanner, the SIEM and the EDR console. Someone is building a spreadsheet to reconcile them. Someone else is turning that spreadsheet into slides. Then a board member asks three questions: How secure is the organization, overall? What is
Cloud & identityStrategy & organizationVulns & exploits
2026-10-02 · BleepingComputer · score 5
Frontline Education is notifying school districts of a data breach after attackers exploited a vulnerability in third-party software to gain unauthorized access to its systems and steal employee information, including Social Security numbers. [...]
NORTHCOMBreach & leaked dataSupply chainVulns & exploits
2026-10-02 · Inside Defense · via TJFSCC Daily · score 5
The Army is asking industry to offer remedies to patch up the energetics pipeline with one site in mind: Blue Grass Army Depot, KY. The Pentagon’s energetics space is hampered by low capacity, old infrastructure, legacy manufacturing and brittle supply chains, a new notice from the portfolio acquisition executive for agile sustainment and ammunition states. “These constraints pose a risk to warfighter readiness, ability to rapidly scale during periods of additional demand, and constrain the ability to field next generation munitions,” the notice states. The service is looking for solutions to onshore production capacity, bulk up supply chains, improve production methods, scale up new formulations and build commercial sustainability. All facilities must be built at Blue Grass, the notice states. The Army earlier this year announced it planned to stand up an energetics “center of excellence” by 2031 at Blue Grass, which would include production of formulations like Research Department Explosive (RDX) and High Melting Explosive (HMX), along with developing next generation explosives and propellants. The Pentagon invested $903 million into the center of excellence in fiscal year 2026…
Supply chainVulns & exploitsUnited Statesvia TJFSCC Daily
2026-10-02 · Inside Defense · via TJFSCC Daily · score 5.25
The Cybersecurity and Infrastructure Security Agency is focusing on securing critical infrastructure with the start of cybersecurity awareness month through promoting cyber activities on incident response to prepare for system disruption to owners and operators. “Our goal is to strengthen American infrastructure against cyber threats, ensuring resilience and security for the next 250 years. So, if your organization owns, operates, supplies, or supports critical infrastructure, you play a vital role,” CISA Acting Director Nick Andersen said in an Oct. 1 webinar kicking off cybersecurity awareness month. The webinar was hosted by the National Cybersecurity Alliance and also featured remarks from NCA executive director Lisa Plaggemier, Darktrace’s Margaret Cunningham, Frame Security’s Nicole Dove and Reps. Jefferson Shreve (R-IN) and Gabe Amo (D-RI). CISA unveiled the theme of the 2026 awareness campaign, “Securing the Next 250,” in an Oct. 1 release . CISA said the theme is intended to “highlight the need for everyone to play their part in strengthening the country's infrastructure against cyber threats.” It follows CISA’s 2026 election infrastructure security plan, published on…
NORTHCOMPACOMCritical infrastructureUnited Statesvia TJFSCC Daily
2026-10-02 · Canadian Centre for Cyber Security · score 5.5
NORTHCOMVulns & exploitsStandards & complianceUnited States
2026-10-02 · CIS / MS-ISAC advisories · score 5.75
A vulnerability has been discovered in Fortinet FortiMail that could allow for arbitrary code execution. Fortinet FortiMail is a secure email gateway that protects organizations from inbound threats including spam, phishing, malware, and business email compromise, while also preventing outbound data loss across physical, virtual, and cloud deployments. Successful exploitation of this vulnerability could allow an unauthenticated attacker to write arbitrary files to the underlying system, which could potentially lead to arbitrary code execution.
Vulns & exploitsSocial engineeringMalware & tooling
2026-10-02 · The Record (Recorded Future) · score 6.75
The group is exploiting a variety of vulnerabilities impacting Microsoft SharePoint, according to a new report from Symantec Threat Hunter Team.
NORTHCOMRansomwareCritical infrastructureVulns & exploitsWarlock / Storm-2603
2026-10-02 · CISA Cybersecurity Advisories · score 7.25
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-102489 Zammad GmbH Zammad Session Fixation Vulnerability CVE-2026-102490 Zammad GmbH Zammad Improper Privilege Management Vulnerability These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. While BOD 26-04 applies only to FCEB…
NORTHCOMVulns & exploitsPolicy & guidanceBreach & leaked dataUnited States
2026-10-02 · DefenseScoop · score 7.5
The Pentagon is pursuing multiple initiatives to enhance its space posture, including the Proliferated Warfighter Space Architecture and the Space Data Network.
SPACECOMNORTHCOMSpace & SATCOMSupply chainUnited States
2026-10-02 · USNI News · via TJFSCC Daily · score 7.5
The Pentagon doubled down on its plans to establish a forward-deployed area denial, anti-access network along the First Island Chain to deter China in the 2026 National Defense Security update. In a Sept. 22 report to the Senate Armed Services Committee on the 2026 NDS, Defense Under Secretary for Policy Elbridge Colby highlighted the department’s efforts to establish a “deterrence by denial” posture in the Indo-Pacific against China. The move is the culmination of attempts within the last decade to prepare American forces for a potential conflict against China, one that would require expansive logistics and missile volleys over the
PACOMNORTHCOMVulns & exploitsUnited StatesChinavia TJFSCC Daily
2026-10-02 · SecurityWeek · score 8
Noteworthy stories that might have slipped under the radar: Kiteworks patches over 100 vulnerabilities, Microsoft publishes 2026 Digital Defense Report, AI finds 24 Android app flaws.
Vulns & exploitsSocial engineeringSpace & SATCOM
2026-10-02 · DefenseScoop · score 10.5
The nation’s counter-drone task force “will not accept a slow-moving bureaucracy when faced with a fast-moving threat,” a spokesperson said.
NORTHCOMSPACECOMPolicy & guidanceCritical infrastructureStrategy & organizationUnited States
2026-10-02 · BleepingComputer · score 10.5
The China-linked ransomware group Warlock targeted a water utility, a telecom provider, a regional government body, and a university by exploiting SharePoint vulnerabilities to gain initial access. [...]
PACOMRansomwareBreach & leaked dataTelecom & cablesWarlock / Storm-2603China
2026-10-02 · The Hacker News · score 11.5
Government and policy organizations across Asia have become the target of a new campaign orchestrated by a China-nexus threat actor. The activity, which has targeted government and policy organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar, involves the deployment of a previously undocumented backdoor codenamed Antino. Cisco Talos is tracking the cluster
PACOMNORTHCOMAPT & espionageMalware & toolingUAT-11587ChinaSE Asia
2026-10-01 · The Record (Recorded Future) · score 2.5
European police said raids against the KillSec ransomware-as-a-service operation included the arrest of a high-profile teen suspect.
EUCOMRansomware
2026-10-01 · SecurityWeek · score 2.75
The US government continues its crackdown on Tren de Aragua over its ATM jackpotting scheme.
NORTHCOMMalware & toolingUnited States
2026-10-01 · Canadian Centre for Cyber Security · score 3
Vulns & exploits
2026-10-01 · Canadian Centre for Cyber Security · score 3
Vulns & exploits
2026-10-01 · Canadian Centre for Cyber Security · score 3
Vulns & exploits
2026-10-01 · BleepingComputer · score 3
An international law enforcement operation dubbed "Operation KillSwitch" seized the KillSec ransomware gang's data leak site and servers, led to three arrests, and identified a 16-year-old as the group's alleged administrator. [...]
RansomwareBreach & leaked data
2026-10-01 · SecurityWeek · score 3
Police took control of KillSec’s leak site and secured at least 110 terabytes of data stolen from victims.
RansomwareBreach & leaked data
2026-10-01 · SecurityWeek · score 3
The flaws were chained to hijack sessions, achieve remote code execution, and elevate privileges to root.
Vulns & exploitsAI & cyber
2026-10-01 · Canadian Centre for Cyber Security · score 3
Vulns & exploits
2026-10-01 · The Hacker News · score 3
This week, the useful words are boring ones: inspect, cache, compile, store, trust. Each sounds harmless. Each can become an attack path when a system does a little more than people expect. A model check can run code. A cache can mix up requests. A public secret can stay useful for years. That is the lesson running through the list. Attackers do not always need a brilliant new trick. They can
Vulns & exploitsAI & cyber
2026-10-01 · SecurityWeek · score 3.25
As AI accelerates vulnerability discovery and exploitation, so-called virtual patching still comes down to defense-in-depth and strong application security fundamentals.
Vulns & exploits
2026-10-01 · Canadian Centre for Cyber Security · score 3.25
Vulns & exploits
2026-10-01 · BleepingComputer · score 3.25
Microsoft says cyberattackers are currently benefiting from artificial intelligence faster than defenders, allowing threat actors to speed up vulnerability discovery, malware development, and post-compromise activity while security teams struggle to keep pace. [...]
Vulns & exploitsMalware & tooling
2026-10-01 · The Hacker News · score 3.5
Every security leader at a bank, insurer, or asset manager has had a version of this conversation: Security wants to eliminate a class of vulnerabilities. Engineering explains what it would take to upgrade the platform where they live. Somebody prices out the regression testing. Somebody else raises the change-freeze calendar. The finding gets an exception, a compensating control, and a date
Supply chainVulns & exploits
2026-10-01 · The Hacker News · score 3.5
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical authentication bypass flaw impacting Cisco Catalyst SD-WAN Manager to its Known Exploited Vulnerabilities (KEV), following reports of active exploitation. The vulnerability, tracked as CVE-2026-76504 (CVSS score: 9.8), could allow an unauthenticated, remote attacker to access an affected system with
NORTHCOMVulns & exploitsUnited States
2026-10-01 · Canadian Centre for Cyber Security · score 3.5
NORTHCOMVulns & exploits
2026-10-01 · The Hacker News · score 3.5
Police in Spain have arrested a 16-year-old whom investigators suspect of running the KillSec ransomware group. KillSec is accused of stealing data from organizations and threatening to publish it on its leak site unless they paid. The 16-year-old was one of 3 people arrested on September 30, when police also took control of that site. Investigators identified him as KillSec's suspected
EUCOMRansomwareBreach & leaked data
2026-10-01 · The Hacker News · score 3.5
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added a critical security flaw impacting Fortinet FortiMail to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation. The vulnerability, tracked as CVE-2026-104286 (CVSS score: 9.8), allows unauthenticated attackers to write arbitrary files on the underlying system. "An improper
NORTHCOMVulns & exploitsUnited States
2026-10-01 · Canadian Centre for Cyber Security · score 4
Vulns & exploitsHacktivism & DDoS
2026-10-01 · CIS / MS-ISAC advisories · score 4
A vulnerability has been discovered in WordPress that could allow arbitrary code on the web server. WordPress is a free, open-source content management system (CMS) that allows you to build and manage websites without needing to write code. Successful exploitation allows an unauthenticated attacker to manipulate the page-template resolution logic to execute local PHP files outside the active theme directory, potentially leading to Remote Code Execution (RCE) under specific conditions.
Vulns & exploitsSupply chain
2026-10-01 · Canadian Centre for Cyber Security · score 4
Vulns & exploitsCloud & identity
2026-10-01 · Canadian Centre for Cyber Security · score 4
Vulns & exploitsBreach & leaked data
2026-10-01 · Industrial Cyber · via TJFSCC Daily · score 4
Bitdefender, a European-based company, announced a partnership with Aruba S.p.A., one of Italy’s IT, cloud and data center...
EUCOMCritical infrastructureCloud & identityvia TJFSCC Daily
2026-10-01 · BleepingComputer · score 4.5
Fortinet is warning customers of a critical FortiMail vulnerability, tracked as CVE-2026-104286, that is being actively exploited in zero-day attacks to execute unauthorized code or commands on vulnerable devices. [...]
Vulns & exploitsPolicy & guidance
2026-10-01 · CERT/CC Vulnerability Notes (Carnegie Mellon SEI) · score 5
Overview An Out-of-bounds Write vulnerability in the InsydeH2O IHISI software used by HP PC BIOS can allow a local attacker with OS kernel privileges to perform arbitrary physical memory writes, including writes to System Management RAM (SMRAM). Because the vulnerable code executes in System Management Mode (SMM), successful exploitation can allow an attacker to modify SMM-protected memory and potentially achieve arbitrary code execution in SMM. Depending on the platform's memory and firmware configuration, the arbitrary physical memory write primitive may also have implications for UEFI firmware update or flash-related operations. Description HP PC BIOS is firmware that initializes and manages hardware components during the boot process and provides runtime services to the operating system and provide the ability to update firmware. The affected system uses InsydeH2O Kernel version 5.5 or earlier. The BIOS includes custom HP SMM handlers that execute in System Management Mode (SMM), a highly privileged CPU execution mode that is isolated from the operating system. CVE-2026-12855 : An Out-of-bounds Write vulnerability in the H19WMIHandlerSmm module (GUID…
NORTHCOMVulns & exploitsSupply chain
2026-10-01 · Industrial Cyber · score 5
New data from Google Threat Intelligence Group (GTIG) found that artificial intelligence is changing the pace of vulnerability...
Vulns & exploitsCritical infrastructureAI & cyber
2026-10-01 · Zscaler ThreatLabz · score 5
Data exfiltrated by leading ransomware groups jumped 275.8% year over year to 896.2 terabytes, according to the Zscaler ThreatLabz 2026 Ransomware Report. That is more than seven times the volume recorded during the 2023–2024 reporting period. As organizations move more sensitive information through modern digital operations, and increasingly through AI-enabled systems, attackers have more high-value targets to steal and more ways to pressure victims once they do.Government, education, and healthcare organizations were among the largest individual data theft incidents observed during the reporting period. Below, we break down what ThreatLabz observed across each sector, including a notable surge in attacks on utilities, and why these industries continue to attract ransomware campaigns. For the full view across industries and threat groups, download the Zscaler ThreatLabz 2026 Ransomware Report. How initial access is changingMany ransomware groups are shifting away from relying solely on malware delivery. ThreatLabz uncovered an initial access broker targeting employees who held manager positions primarily in non-technical departments such as accounting/finance, sales, operations,…
RansomwareMalware & toolingCritical infrastructure
2026-10-01 · Canadian Centre for Cyber Security · score 5
Vulns & exploitsICS / OT
2026-10-01 · SpaceNews · via TJFSCC Daily · score 5
L3Harris’ contract for executive aircraft satcom grows to $462 million L3Harris’ contract for executive aircraft satcom grows to $462 million
SPACECOMSpace & SATCOMvia TJFSCC Daily
2026-10-01 · CIS / MS-ISAC advisories · score 5.25
A vulnerability has been discovered in Kiteworks EPG (Email Security Gateway) that could allow for arbitrary code execution. Kiteworks Email Protection Gateway (EPG) is a cloud-based security solution that automates end-to-end encryption, decryption, and policy enforcement for inbound and outbound enterprise emails. A combination of input-handling flaws in publicly reachable endpoints of the Kiteworks Email Protection Gateway may potentially allow an unauthenticated remote attacker to achieve arbitrary code execution. Successful exploitation of this vulnerability could allow for arbitrary code execution as root, which may lead to the complete compromise of the affected device.
Vulns & exploitsCloud & identityStandards & compliance
2026-10-01 · Socket · score 5.25
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.
EUCOMNORTHCOMMalware & toolingPolicy & guidanceRussia
2026-10-01 · Nikkei Asia · via TJFSCC Daily · score 5.25
PACOMVulns & exploitsJapanvia TJFSCC Daily
2026-10-01 · Canadian Centre for Cyber Security · score 5.5
NORTHCOMVulns & exploitsStandards & complianceUnited States
2026-10-01 · Malwarebytes Labs · score 5.5
Three independent labs, three standout results: a perfect score, top certification, and every threat stopped before it ran.
NORTHCOMMalware & toolingRansomwareSocial engineering
2026-10-01 · Industrial Cyber · score 5.5
The Alliance for Critical Infrastructure (ACI) expanded its membership to nearly 50 companies across six U.S. critical infrastructure...
NORTHCOMCritical infrastructureSupply chainAI & cyberUnited States
2026-10-01 · CISA Cybersecurity Advisories · score 5.75
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to escalate privileges or overwrite files. The following versions of ABB Protection and Control IED Manager PCM600 are affected: Protection and Control IED Manager PCM600 <=2.14 (CVE-2026-15952, CVE-2026-15953) CVSS Vendor Equipment Vulnerabilities v3 6.4 ABB ABB Protection and Control IED Manager PCM600 Incorrect Permission Assignment for Critical Resource, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Background Critical Infrastructure Sectors: Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Switzerland Vulnerabilities Expand All + CVE-2026-15952 A vulnerability exists in the Scheduler Service installed with PCM600. The service executes under the LocalSystem account while permissions are granted to standard PCM600 users through membership in the local users group. An attacker with local access and valid user credentials may exploit this vulnerability to elevate privileges and obtain control of the affected host. View CVE Details Affected Products ABB Protection and Control IED Manager PCM600 Vendor: ABB Product Version: ABB…
Vulns & exploitsCritical infrastructureSupply chain
2026-10-01 · CISA Cybersecurity Advisories · score 6
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker tointercept and read sensitive information, including credentials andsession data. The following versions of Johnson Controls EasyIO Neo Series EC and CW Controllers are affected: EasyIO Neo Series EC Controllers V3.3b62 (CVE-2026-64893) EasyIO Neo Series EC Controllers V3.3b63 (CVE-2026-64893) EasyIO Neo Series CW Controllers V3.3b24 (CVE-2026-64893) EasyIO Neo Series CW Controllers V3.3b25 (CVE-2026-64893) CVSS Vendor Equipment Vulnerabilities v3 5.4 Johnson Controls Johnson Controls EasyIO Neo Series EC and CW Controllers Cleartext Transmission of Sensitive Information Background Critical Infrastructure Sectors: Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Ireland Vulnerabilities Expand All + CVE-2026-64893 Johnson Controls is aware of a vulnerability in EasyIO Neo which may allow an attacker to intercept and read sensitive information, including credentials and session data, transmitted in cleartext over the network. Successful exploitation could result in…
Vulns & exploitsCritical infrastructureSupply chain
2026-10-01 · Socket · score 6
Capital One is partnering with Socket to proactively secure its open source supply chain.
NORTHCOMSupply chainVulns & exploitsAI & cyber
2026-10-01 · Industrial Cyber · score 6
ARIA Cybersecurity, a CSPi business, announced its second deployment within the production infrastructure of a leading pharmaceutical producer....
Vulns & exploitsAPT & espionageRansomware
2026-10-01 · Industrial Cyber · via TJFSCC Daily · score 6
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) launched its 2026 Cybersecurity Awareness Month campaign under the theme...
NORTHCOMSPACECOMCritical infrastructureUnited Statesvia TJFSCC Daily
2026-10-01 · SpaceNews · via TJFSCC Daily · score 6.25
We’ve spent eight years hacking satellites. Here’s what the space industry needs to know now.
SPACECOMSpace & SATCOMvia TJFSCC Daily
2026-10-01 · SpaceWatch.Global · via Space Watch · score 6.25
From Mission-K in Kalkar, Marco Schmidt of Trend AI joins Torsten Kriening to explain why cyber and space are now intertwined domains of hybrid warfare, how the 2022 satellite communications attack actually unfolded, and why the ground segment — not the satellite — is where the real threat lies.
SPACECOMSpace & SATCOMvia Space Watch
2026-10-01 · Industrial Cyber · score 6.5
A new report from the U.S. Government Accountability Office (GAO) found that industry representatives from three critical infrastructure...
NORTHCOMCritical infrastructurePolicy & guidanceStandards & complianceUnited States
2026-10-01 · Industrial Cyber · score 6.5
Intelligent automation company Gluware announced Gluware IoMT Exposure Management, bringing its proven automation platform to the Internet of...
NORTHCOMVulns & exploitsBreach & leaked dataStandards & complianceUnited States
2026-10-01 · Microsoft Security / MSTIC · score 6.5
According to this year’s Microsoft Digital Defense Report, government agencies and services were the sector most impacted by cyber threats in 2026, accounting for 27% of observed activity, up from 17% in 2025.
Vulns & exploitsCritical infrastructureAPT & espionage
2026-10-01 · Via Satellite · via Space Watch · score 6.5
Iceye, the Finnish space company known for building synthetic aperture radar (SAR) satellites is venturing into communication satellites — planning to build sovereign satcom satellites for governments through a new partnership […]
SPACECOMSpace & SATCOMvia Space Watch
2026-10-01 · CISA Cybersecurity Advisories · score 6.75
View CSAF Summary The following versions of CISA Malcolm are affected: Malcolm CVSS Vendor Equipment Vulnerabilities v3 8.8 CISA CISA Malcolm Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Server-Side Request Forgery (SSRF), Authentication Bypass by Spoofing, Missing Authorization, Missing Authentication for Critical Function, Incorrect Authorization, Use of Default Credentials, Improper Certificate Validation, URL Redirection to Untrusted Site ('Open Redirect'), Dependency on Vulnerable Third-Party Component, Use of Password Hash With Insufficient Computational Effort Background Critical Infrastructure Sectors: Energy, Information Technology, Water and Wastewater Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-90443 A web interface reflects a portion of the request URL into a script context and a hyperlink attribute without adequate encoding, and does not require authentication to reach. This allows an…
NORTHCOMSupply chainVulns & exploitsCritical infrastructureUnited States
2026-10-01 · Inside Defense · via TJFSCC Daily · score 6.75
BAE Systems Information and Electronic Systems Integration has been awarded a $146.69 million Air Force contract for its Eagle Passive Active Warning Survivability System, according to a recent notice . Procurement of the electronic warfare hardware is associated with F-15EX Eagle II Lots 7 and 8, the service wrote in its Sept. 30 announcement. EPAWSS brings improved radar warning, geolocation, situational awareness, self-protection and jamming compared to the legacy Tactical Electronic Warfare System found on F-15E Strike Eagles. The Air Force on Sept. 29 meanwhile awarded Boeing a $2.38 billion contract to produce 22 F-15EX Eagle II's, making use of reconciliation money made available by last year's One Big Beautiful Bill. That contract covers Lot 7 of the program and brings the total number of aircraft Boeing is currently expected to produce for the service to 120. In its fiscal year 2027 budget request, the Air Force introduced a plan to nearly double its overall F-15EX buy -- from 129 jets to 267 -- to replace the older F-15E fleet. EPAWSS work is expected to be complete by Aug. 31, 2030. Roughly $58.8 million of procurement dollars from FY-25 and FY-26 have been made…
OPSEC & personal securitySpace & SATCOMvia TJFSCC Daily
2026-10-01 · Cisco Talos · score 7
What really frustrates an adversary? Eight Cisco Talos researchers share practical ways to make their next move slower and riskier. From deception and behavioral detection to breaking attack dependencies and resisting manufactured urgency.
NORTHCOMAI & cyberPolicy & guidanceCritical infrastructure
2026-10-01 · CISA Cybersecurity Advisories · score 7
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to gain access to sensitive information that could be used to conduct further attacks against the system. The following versions of Johnson Controls EasyIO Neo Series EC and CW Controllers are affected: EasyIO Neo Series EC Controllers V3.3b63 (CVE-2026-64892) EasyIO Neo Series EC Controllers V3.3b62 (CVE-2026-64892) EasyIO Neo Series CW Controllers V3.3b25 (CVE-2026-64892) EasyIO Neo Series CW Controllers V3.3b24 (CVE-2026-64892) CVSS Vendor Equipment Vulnerabilities v3 3.5 Johnson Controls Johnson Controls EasyIO Neo Series EC and CW Controllers Exposure of Sensitive Information to an Unauthorized Actor Background Critical Infrastructure Sectors: Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Ireland Vulnerabilities Expand All + CVE-2026-64892 Johnson Controls is aware of a vulnerability in EasyIO Neo Series EC and CW Controllers relating to an attacker gaining access to sensitive information that could be used to conduct further attacks against the system.…
NORTHCOMVulns & exploitsBreach & leaked dataPolicy & guidance
2026-10-01 · South China Morning Post (China) · via TJFSCC Daily · score 7
Two giant pandas arrived in the US following Chinese President Xi Jinping’s visit to Washington, continuing a decades-old tradition in which the beloved fuzzy ambassadors have become symbols of China’s ties with countries around the world. Zoo Atlanta announced the arrival of giant pandas Ping Ping and Fu Shuang on Sunday, saying it was “overjoyed” to welcome the pair after the zoo’s previous 25-year partnership with China ended in 2024. Xi said during his US visit that the pandas would be sent...
PACOMNORTHCOMAPT & espionageChinaUnited Statesvia TJFSCC Daily
2026-10-01 · CISA Cybersecurity Advisories · score 7.25
View CSAF Summary Successful exploitation of these vulnerabilities could enable attackers to gain unauthorized administrative control over vulnerable charging stations or disrupt charging services through denial-of-service attacks. The following versions of Monta monta.app are affected: monta.app vers:all/* (CVE-2026-95102, CVE-2026-97363, CVE-2026-97212, CVE-2026-93474) CVSS Vendor Equipment Vulnerabilities v3 9.4 Monta Monta monta.app Missing Authentication for Critical Function, Improper Restriction of Excessive Authentication Attempts, Insufficient Session Expiration, Insufficiently Protected Credentials Background Critical Infrastructure Sectors: Energy, Transportation Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: Netherlands Vulnerabilities Expand All + CVE-2026-95102 WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit this weakness to gain unauthorized access to sensitive data or perform unauthorized actions. Given that no authentication is required, this can lead to privilege escalation and potentially compromise the security of the entire system.…
EUCOMVulns & exploitsSocial engineeringPolicy & guidance
2026-10-01 · CISA Cybersecurity Advisories · score 7.5
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-104286 Fortinet FortiMail Path Traversal Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management…
NORTHCOMVulns & exploitsPolicy & guidanceBreach & leaked dataUnited States
2026-10-01 · CyberScoop · score 7.5
The teenager-run cybercrime group victimized roughly 500 organizations in less than two years.
EUCOMNORTHCOMRansomwareBreach & leaked dataPolicy & guidanceUnited StatesUK
2026-10-01 · SpaceWatch.Global · via Space Watch · score 7.5
ICEYE is expanding beyond satellite-based intelligence into communications through a new partnership with Nokia to develop secure, sovereign broadband systems for governments and defense customers. The Finnish companies plan to combine ICEYE’s satellite and constellation capabilities with Nokia’s secure networking technology, with the first communications satellites expected to launch in 2028.
SPACECOMSpace & SATCOMvia Space Watch
2026-10-01 · CISA Cybersecurity Advisories · score 7.75
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to the database, execute arbitrary code on the host with the highest level of privilege, or gain control of the physical access-control system. The following versions of Armatura LLC Armatura One are affected: Armatura One <4.7.2 (CVE-2023-46604, CVE-2026-94591, CVE-2026-94592, CVE-2026-94593, CVE-2026-94594) Armatura One (USA) <4.6.1 (CVE-2023-46604, CVE-2026-94591, CVE-2026-94592, CVE-2026-94593, CVE-2026-94594) CVSS Vendor Equipment Vulnerabilities v3 9.8 Armatura LLC Armatura LLC Armatura One Deserialization of Untrusted Data, Use of Hard-coded Cryptographic Key, Use of Hard-coded Credentials, Insertion of Sensitive Information into Log File Background Critical Infrastructure Sectors: Communications, Critical Manufacturing, Energy, Transportation Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2023-46604 Armatura One embeds Apache ActiveMQ, exposing its OpenWire protocol listener on the network by default. This embedded version is affected by CVE-2023-46604, a deserialization flaw in…
NORTHCOMVulns & exploitsPolicy & guidanceCritical infrastructureUnited States
2026-10-01 · The Register — security · score 8
Institutions told to trace who is really financing their work or risk falling foul of national security law
PACOMEUCOMAPT & espionageChinaUK
2026-10-01 · Inside Defense · via TJFSCC Daily · score 8
The Space Force awarded L3Harris $461.9 million for commercial satellite communications connectivity on executive airlift aircraft, according to a Pentagon notice . The firm-fixed-price definitization contracting action “supports authorized government personnel and is expected to be completed by Oct. 31, 2028,” the notice states. At the time of the award, the service obligated $62.3 million in fiscal year 2026 operations and maintenance funds through the Space Force portfolio acquisition executive for satellite communications and positioning, navigation and timing. The Air Force would not provide specifics to Inside Defense on which aircraft are related to the contract.
SPACECOMSpace & SATCOMUnited Statesvia TJFSCC Daily
2026-10-01 · Inside Defense · via TJFSCC Daily · score 8.5
Air Force expects deliveries of new deployable battle management centers by year's end Pentagon to launch new Autonomous Warfare Command Cotton calls for review of military shipping channels after F-35 parts landed in Hong Kong FY-27 funding purgatory puts CCA production at a standstill Miller nominated for head of SPACECOM L3Harris awarded $462M for executive airlift SATCOM connectivity Air Force SAB to hold closed meetings to begin FY-27 studies Lockheed awarded $15.7M for Next Gen OPIR-GEO Raytheon wins $20.7 billion AMRAAM deal as U.S., allies ramp production Stratolaunch adds 777 for hypersonic tests Space Force starting search for new PNT user equipment Northrop awarded $111M for Sentinel missile program EMD DOD launches third drone competition phase as stopgap funding looms Counter-drone task force awards contracts with $7B ceiling for Domestic Shield initiative Hegseth taps Musk, Luckey and Gingrich for new 'future of warfare' panel Anthropic weighs further review after appeals court backs DOD risk designation Pentagon establishes new team to target waste, bureaucracy across DOD BAE awarded $146.7M contract to add EPAWSS to Lot 7, 8 F-15EX Boeing awarded $2B for 22 F-15EX…
SPACECOMNORTHCOMSpace & SATCOMUnited Statesvia TJFSCC Daily
2026-10-01 · Dark Reading · score 9
A year-old Chinese threat actor looks like a cybercrime gang, acts like a state-associated APT, and attacks organizations in unexpected places.
PACOMRansomwareAPT & espionageWarlock / Storm-2603China
2026-10-01 · SecurityWeek · score 9
The China-based hacking group has been exploiting SharePoint vulnerabilities since July 2025.
PACOMCritical infrastructureCloud & identityVulns & exploitsWarlock / Storm-2603China
2026-10-01 · CISA Cybersecurity Advisories · score 9.5
View CSAF Summary Successful exploitation of these vulnerabilities could allow attackers to manipulate device configurations, trigger unauthorized behaviors, and access sensitive information such as device credentials, owner details, and network data without proper authorization. The following versions of Meari IoT Cloud Platform OpenAPI Service are affected: IoT Cloud Platform OpenAPI Service vers:all/* (CVE-2026-101104, CVE-2026-96613) CVSS Vendor Equipment Vulnerabilities v3 7.7 Meari Meari IoT Cloud Platform OpenAPI Service Missing Authorization Background Critical Infrastructure Sectors: Commercial Facilities, Information Technology Countries/Areas Deployed: Worldwide Company Headquarters Location: China Vulnerabilities Expand All + CVE-2026-101104 The Meari IoT Cloud Platform OpenAPI Service is vulnerable to an authorization flaw that allows authenticated users to manipulate the configurations of devices they do not own. This vulnerability enables attackers to perform unauthorized actions, such as altering device settings or triggering unintended behaviors, without verifying ownership or permissions. View CVE Details Affected Products Meari IoT Cloud Platform OpenAPI…
PACOMVulns & exploitsApps & devicesCloud & identityChina
2026-10-01 · CISA Known Exploited Vulnerabilities · score 10.25
Zammad GmbH Zammad Improper Privilege Management Vulnerability. Zammad GmbH Zammad contains an improper privilege management vulnerability that can allow the local zammad user to escalate privileges to root. This vulnerability can be chained with CVE-2026-102489. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Due 2026-10-05.
NORTHCOMVulns & exploitsPolicy & guidanceBreach & leaked dataUnited StatesKEV
2026-10-01 · CISA Known Exploited Vulnerabilities · score 10.25
Zammad GmbH Zammad Session Fixation Vulnerability. Zammad GmbH Zammad contains a session fixation vulnerability that can lead to remote code execution as the zammad user. This vulnerability can be chained with CVE-2026-102490. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Due 2026-10-05.
NORTHCOMVulns & exploitsPolicy & guidanceBreach & leaked dataUnited StatesKEV
2026-10-01 · The Register — security · score 11.5
RUSI wants procurement rethink that could put US suppliers under scrutiny too
EUCOMPACOMSupply chainTelecom & cablesStandards & complianceChinaUK
2026-10-01 · The Guardian (World) · via TJFSCC Daily · score 11.75
Hostile states could access cameras, microphones or GPS, says intelligence agency amid concerns over Chinese imports Drivers have been warned that the smart features built into modern cars such as microphones, cameras and GPS trackers could be used by hostile states to spy on them. The Dutch General Intelligence and Security Service (AIVD) called for “awareness of espionage risks around modern vehicles”, including microphones that can by switched on remotely to listen to conversations.
NORTHCOMPACOMAPT & espionageSpace & SATCOMChinavia TJFSCC Daily
2026-10-01 · Industrial Cyber · score 13.5
New data from Symantec observed that the China-nexus group behind Warlock ransomware, tracked as Longlegs or Storm-2603, has...
NORTHCOMPACOMTelecom & cablesVulns & exploitsRansomwareWarlock / Storm-2603Linen / Violet TyphoonUnited StatesChina
2026-10-01 · Risky Business News · score 14.5
In other news: Ransomware attack could have crippled South Africa's air traffic operations; US sanctions Venezuelan ATM hackers; Chinese APT targets AI experts.
EUCOMPACOMRansomwareVulns & exploitsAPT & espionageQilinAkiraChinaAustralia
2026-09-30 · BleepingComputer · score 2.5
Remote access software company TeamViewer warned customers on Tuesday to immediately patch a set of high-severity vulnerabilities affecting its client and host software. [...]
Vulns & exploits
2026-09-30 · SecurityWeek · score 2.5
Several security firms have confirmed seeing exploitation of the NetScaler vulnerabilities CVE-2026-88771 and CVE-2026-88772.
Vulns & exploits
2026-09-30 · Rapid7 blog · score 3.5
Overview On September 30, 2026, Cisco published a security advisory for CVE-2026-76504 , a critical API authentication bypass vulnerability affecting Cisco Catalyst SD-WAN Manager. The vulnerability has a CVSSv3.1 score of 9.8 and results from improper handling of URL encoding ( CWE-177 ). An unauthenticated, remote attacker can send a crafted HTTP request that bypasses an authentication rule for a specific API endpoint, gaining access to the API with the privileges of the admin user. According to Cisco, CVE-2026-76504 is being actively exploited in the wild; Cisco PSIRT became aware of the activity in September 2026. Cisco Catalyst SD-WAN Manager systems with ports exposed to the internet are at risk of compromise. The vulnerability affects the product regardless of system configuration, and Cisco has not provided a workaround, however vendor supplied updates are available. Rapid7 strongly recommends that organizations upgrade affected systems to a fixed release on an emergency basis, outside of normal patch cycles, and investigate internet-facing systems for signs of exploitation. Cisco Catalyst SD-WAN Manager was also affected by two critical, unauthenticated peering…
Vulns & exploitsSupply chain
2026-09-30 · The Hacker News · score 3.5
Threat actors have weaponized a now-patched security flaw in Zimbra Collaboration Suite (ZCS) to deploy web shells and access mailbox data, according to findings from the Microsoft Security Research team. The attack exploits CVE-2026-73570 (CVSS score: 8.9), an unauthenticated operating system command injection flaw that can lead to remote code execution when Simple Network Management Protocol
Vulns & exploitsMalware & tooling
2026-09-30 · The Hacker News · score 3.5
Threat actors have been observed exploiting a critical pre-authentication command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway to drop web shells and attempt theft of configuration data. LevelBlue's Threat Hunt Operations & Research (THOR) team, which analyzed the exploitation activity across multiple customer environments, said it identified malicious NetScaler
Malware & toolingVulns & exploits
2026-09-30 · BleepingComputer · score 4
The Dutch Institute for Vulnerability Disclosure (DIVD) says that the breach of its network was possible by exploiting a chain of two zero-day vulnerabilities in the open-source Zammad ticketing system. [...]
Vulns & exploitsBreach & leaked dataAI & cyber
2026-09-30 · BleepingComputer · score 4.25
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a new critical vulnerability in MikroTik RouterOS that could lead to remote code execution or cause a denial-of-service condition. [...]
NORTHCOMVulns & exploitsHacktivism & DDoSUnited States
2026-09-30 · BleepingComputer · score 4.25
Cryptocurrency exchange Bitget revealed today that attackers who stole $387.5 million last week breached its systems after exploiting a zero-day flaw in third-party security products. [...]
Supply chainVulns & exploitsBreach & leaked data
2026-09-30 · The Hacker News · score 4.5
Security researchers have published the first public proof-of-concept for CVE-2026-86950, an Apple CoreGraphics flaw Apple says may have been used in attacks against specific targeted individuals. The trigger is a malicious PDF with a crafted embedded font that crashes unpatched iPhones and Macs. The code causes a crash, not an execution error. Turning the memory corruption into a working
NORTHCOMVulns & exploitsApps & devices
2026-09-30 · CIS / MS-ISAC advisories · score 4.75
A vulnerability has been discovered in Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage) that could allow for authentication bypass. Cisco Catalyst SD-WAN Manager is the centralized dashboard used to monitor and manage SD-WAN fabric devices, in some deployments up to several thousand devices from a single console. An attacker could exploit this vulnerability by sending a specially crafted HTTP request with a URI-encoded character to the Manager's API, which could allow the request to skip an authentication rule intended to restrict access to a specific endpoint. Successful exploitation of this vulnerability could result in an unauthenticated, remote attacker gaining admin-level access to the affected system's API, and by extension the ability to view or modify the configuration of every SD-WAN device that Manager instance controls. This vulnerability affects the product regardless of device configuration; there is no feature toggle or configuration setting that removes the exposure.
NORTHCOMVulns & exploitsBreach & leaked data
2026-09-30 · CIS / MS-ISAC advisories · score 5
A vulnerability has been discovered in Apple products that could allow for arbitrary code execution. macOS Sequoia (macOS 15) is an operating system version for Mac computers released by Apple in late 2024. macOS Tahoe (macOS 26) is an operating system version for Mac computers released by Apple in late 2025. iOS is Apple's mobile operating system. IPadOS is Apple's mobile operating system exclusively for its iPad line of tablet computers. Successful exploitation of the vulnerability could allow for arbitrary code execution. Depending on the privileges associated with the user an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.
Vulns & exploitsApps & devices
2026-09-30 · BleepingComputer · score 5.5
The Russian state actor Star Blizzard has been using a new malware installation tactic dubbed "RedFlick" to deploy its signature CosmicPulse backdoor. [...]
EUCOMNORTHCOMMalware & toolingAPT & espionageRussia
2026-09-30 · The Hacker News · score 5.75
Cryptocurrency exchange Bitget on Wednesday confirmed that attackers who stole $387.5 million last week exploited a zero-day flaw in third-party security products, citing ongoing investigation findings from SlowMist. "Their investigation identified malicious activity involving third-party security products, including a zero-day vulnerability, and recovered a customized tool used by the attacker
NORTHCOMSupply chainVulns & exploitsDPRK & crypto theft
2026-09-30 · The Register — security · score 6
It's 2 am. Do you know what your teen is doing?
NORTHCOMCloud & identityVulns & exploitsPolicy & guidance
2026-09-30 · Risky Business News · score 6
Your weekly dose of Seriously Risky Business news is written by Tom Uren and edited by Patrick Gray and Amberleigh Jack. This week's edition is sponsored by PortSwigger . You can hear a podcast discussion of this newsletter by searching for "Risky Business News" in your podcatcher
NORTHCOMPACOMVulns & exploitsAustralia
2026-09-30 · The Record (Recorded Future) · score 6.25
'Hit and run' iPhone malware known as DarkSword is part of a wave of Russian attacks on iOS and Android devices, according to Ukraine's SSSCIP.
EUCOMApps & devicesVulns & exploitsMalware & toolingUkraineRussia
2026-09-30 · Microsoft Security / MSTIC · score 6.25
Microsoft Threat Intelligence examines CVE-2026-73570 exploitation in Zimbra, including observed attack paths, detection opportunities, and mitigation guidance.
EUCOMNORTHCOMVulns & exploitsMalware & toolingPolicy & guidance
2026-09-30 · Dark Reading · score 7.5
The APT actor is using a new tactic, dubbed "RedFlick," against Ukrainian-linked targets such as NGOs, think tanks, and journalists to deploy its CosmicPulse backdoor.
EUCOMNORTHCOMSocial engineeringAPT & espionageMalware & toolingRussiaUkraine
2026-09-30 · CISA Cybersecurity Advisories · score 7.5
CISA added Cisco SD-WAN Manager CVE-2026-76504 (auth bypass to admin) and FortiMail CVE-2026-104286 (unauthenticated file write) to KEV on 30 Sep; both were zero-days.
Both sit at the edge of partner networks.
Consider confirming with the S6 that neither is internet-exposed.
NORTHCOMVulns & exploitsUnited StatesAI-curated
2026-09-30 · Industrial Cyber · via TJFSCC Daily · score 7.5
Cyware, vendor of agentic AI-powered operational threat intelligence and collective defense, today announced its partnership with WaterISAC, which...
NORTHCOMCritical infrastructureAI & cyberICS / OTUnited Statesvia TJFSCC Daily
2026-09-30 · Infosecurity Magazine · score 7.75
MI5 has issued a rare warning to UK academics contributing to the China General Technology Research Institute
PACOMEUCOMAPT & espionageChinaUK
2026-09-30 · The Guardian (World) · via TJFSCC Daily · score 7.75
Institutions have for years turned to China for funding opportunities but national security concerns are mounting MI5 issues spy alert to UK universities over Chinese front company stealing research The security alert issued by MI5 regarding a Chinese state-owned conglomerate accused of conducting espionage in the UK reveals the extent to which British intelligence remains concerned about Beijing’s influence, and risks casting a shadow over UK-China cooperation at a time when the bilateral relationship is enjoying a revival. The UK’s domestic security service on Wednesday warned researchers and academics to cease work with the China Academy of General Technology (CAGT), an organisation MI5 described as a “significant threat”.
PACOMEUCOMAPT & espionageChinaUKvia TJFSCC Daily
2026-09-30 · The Guardian (World) · via TJFSCC Daily · score 8.25
Security service says academics should stop taking grants from and working with firm backed by China’s intelligence service MI5 China alert will send chill through UK’s cash-strapped universities China’s intelligence service used a front company to pay grants to British universities and steal crucial research about technology projects, MI5 said on Wednesday in a rare public espionage warning. Britain’s domestic security service said researchers and academics should cease work with the China General Technology Research Institute (CGTRI), sometimes also known as the China Academy of General Technology (CAGT). MI5 believes it poses a “significant threat”.
EUCOMPACOMAPT & espionageUKChinavia TJFSCC Daily
2026-09-30 · AhnLab ASEC · score 9.5
ASEC Blog publishes Ransom & Dark Web Issues Week 1, October 2026 Dutch Police Confirm Arrest of 24-Year-Old Man in ShinyHunters Hacking Investigation [1] [2] Ulose Claims Data Leak from a South Korean General Hospital Qilin Ransomware Attack on a Japanese Freight and Logistics Company
PACOMRansomwareBreach & leaked dataQilinShinyHuntersJapanROK
2026-09-30 · SecurityWeek · score 9.75
The state-sponsored group has launched larger-scale phishing campaigns to deploy the CosmicPulse backdoor.
EUCOMNORTHCOMAPT & espionageMalware & toolingSocial engineeringRussia
2026-09-30 · CISA Known Exploited Vulnerabilities · score 10.25
Fortinet FortiMail Path Traversal Vulnerability. Fortinet FortiMail contains a path traversal and an improper neutralization of NULL byte or NULL character vulnerability that may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Due 2026-10-04.
NORTHCOMVulns & exploitsPolicy & guidanceBreach & leaked dataUnited StatesKEV
2026-09-30 · CyberScoop · score 11.5
Internet-exposed tech, PLCs, outside integrators and inside protections are all factors the water sector’s information sharing and analysis center is watching.
NORTHCOMPACOMICS / OTVulns & exploitsCritical infrastructureUnited StatesChina
2026-09-30 · Cisco Talos · score 12
Cisco Talos uncovered a cluster of activity we track as UAT-11587 targeting government and policy organizations across Asia, including in Taiwan, India, the Philippines, and Cambodia, to deliver a previously undocumented backdoor referred to as “Antino” in developer artifacts.
PACOMNORTHCOMMalware & toolingSocial engineeringCloud & identityUAT-11587ChinaPhilippines
2026-09-29 · Dark Reading · score 2.5
The critical vulnerabilities, which impact default configurations of NetScaler products, essentially give attackers a skeleton key to customers' networks.
Vulns & exploits
2026-09-29 · Canadian Centre for Cyber Security · score 3
Vulns & exploits
2026-09-29 · Canadian Centre for Cyber Security · score 3
Vulns & exploits
2026-09-29 · Canadian Centre for Cyber Security · score 3
Vulns & exploits
2026-09-29 · Canadian Centre for Cyber Security · score 3
Vulns & exploits
2026-09-29 · Canadian Centre for Cyber Security · score 3
Vulns & exploits
2026-09-29 · Dark Reading · score 3
A patched Unsloth Studio vulnerability allows malicious AI models to execute arbitrary Python code during inspection, via the trust_remote_code setting.
Vulns & exploitsAI & cyber
2026-09-29 · The Hacker News · score 3
Unknown threat actors have been observed exploiting a newly patched security flaw in Citrix NetScaler ADC and NetScaler Gateway appliances to target organizations in North America and Europe. The activity, observed by Mandiant Consulting and Google Threat Intelligence Group (GTIG) in September 2026, has targeted government, financial services, technology, education, and legal and professional
EUCOMVulns & exploits
2026-09-29 · SecurityWeek · score 3
Roughly a dozen vulnerabilities have been patched in each of the open source cryptographic libraries.
Vulns & exploitsSupply chain
2026-09-29 · BleepingComputer · score 3.25
Cybersecurity firms say attackers exploited the Citrix NetScaler CVE-2026-88772 zero-day to deploy custom web shells and tunneling malware, gain root access, steal credentials, and spread into internal networks. [...]
Vulns & exploitsMalware & tooling
2026-09-29 · SecurityWeek · score 3.5
The AIxCC competition winner will analyze messaging app code and compiled binaries for vulnerabilities, with technology that could also help commercial customers secure their software.
Vulns & exploits
2026-09-29 · Huntress · score 3.5
Huntress SOC found a threat actor exploiting a file upload flaw in recreation management to breach 3 municipal servers and steal payment data.
NORTHCOMMalware & toolingBreach & leaked data
2026-09-29 · ESET WeLiveSecurity · score 3.75
Autonomous AI agents go on a hacking spree, and Microsoft ships what used to be a year's worth of security patches in one go – here's how to keep pace
NORTHCOMVulns & exploitsAI & cyber
2026-09-29 · CISA Cybersecurity Advisories · score 4
View CSAF Summary Successful exploitation of this vulnerability may allow attackers to achieve remote command execution on affected devices, potentially with root privileges, leading to full compromise of the camera system. The following versions of VIVOTEK Camera Firmware are affected: V Series model_FD9187 (CVE-2026-22755) V Series model_FD9189 (CVE-2026-22755) V Series model_FD9365 (CVE-2026-22755) V Series model_FD9387 (CVE-2026-22755) V Series model_FD9389 (CVE-2026-22755) V Series model_FD9391 (CVE-2026-22755) C Series model_FE9180 (CVE-2026-22755) V Series model_FE9191 (CVE-2026-22755) V Series model_FE9382 (CVE-2026-22755) V Series model_FE9391 (CVE-2026-22755) V Series model_IB9365 (CVE-2026-22755) V Series model_IB9387 (CVE-2026-22755) V Series model_IB9389 (CVE-2026-22755) V Series model_IB939 (CVE-2026-22755) V Series model_IP9165 (CVE-2026-22755) V Series model_IP9171 (CVE-2026-22755) S Series model_IP9172 (CVE-2026-22755) V Series model_IP9181 (CVE-2026-22755) V Series model_IP9191 (CVE-2026-22755) V Series model_IT9389 (CVE-2026-22755) V Series model_MA9321 (CVE-2026-22755) V Series model_MA9322 (CVE-2026-22755) S Series model_MS9321 (CVE-2026-22755) V Series…
Supply chainVulns & exploits
2026-09-29 · Canadian Centre for Cyber Security · score 4.25
Vulns & exploitsSupply chain
2026-09-29 · BleepingComputer · score 4.25
Custom variants of OpenAI's ChatGPT promoted in sponsored Google results are directing unsuspecting users to malicious sites that use ClickFix attacks to deliver malware. [...]
Malware & toolingSocial engineeringAI & cyber
2026-09-29 · Dark Reading · score 4.25
As aviation infrastructure suffers more cyberattacks, air traffic systems are the latest target, with a ransomware toolkit installed on at least one operational network.
AFRICOMCritical infrastructureRansomware
2026-09-29 · Zscaler ThreatLabz · score 4.25
Ransomware is no longer defined only by how many organizations get hit. The most important shifts are happening beneath the headline victim counts; in how attackers gain access, who they target first, and how much data they steal once they’re in.The newly released Zscaler ThreatLabz 2026 Ransomware Report examines ransomware activity from April 2025 through March 2026, with a focus on groups and affiliates, victim targeting, attack techniques, data theft, and payment patterns.The findings reinforce a clear reality for defenders: ransomware’s leverage is growing by the terabyte, while initial access is increasingly driven by repeatable playbooks that abuse trusted enterprise tools and trusted people. At the same time, the economics are shifting: total known ransom payments fell year over year, but the average payment increased, suggesting attackers are extracting more from the victims that do pay.This blog highlights a subset of the most significant findings and implications for security teams. The full report provides deeper analysis of ransomware trends, case studies, and practical guidance to disrupt ransomware across the attack lifecycle. 5 key takeaways for security teams in…
RansomwarePolicy & guidance
2026-09-29 · The Hacker News · score 4.5
Kiteworks on Monday said it worked with federal intelligence authorities over the weekend as it identified and addressed a critical security vulnerability during the scheduled precautionary shutdown. "During the shutdown, this activity led to the discovery of a previously unknown critical vulnerability confined to a capability that is enabled for less than 1% of the customer base," the company
NORTHCOMVulns & exploitsUnited States
2026-09-29 · BBC News (World) · via TJFSCC Daily · score 4.5
He was arrested in Russia in 2023 and later sentenced to 16 years on espionage charges.
EUCOMNORTHCOMAPT & espionageRussiavia TJFSCC Daily
2026-09-29 · Microsoft Security / MSTIC · score 5
Explore how Storm-3068 turned a compromised identity into broader cloud access and the steps organizations can take to defend their identities, pipelines, and cloud infrastructure.
NORTHCOMCloud & identityMalware & toolingCritical infrastructure
2026-09-29 · SANS Internet Storm Center · score 5.25
Starting yesterday, our sensors picked up a small number of scans for "wordfence-waf.php". This particular script is used by Wordfence, a solution to protect WordPress sites. During the Wordfence install, the wordpress-waf.php file will be created in the site&#;x26;#;39;s root directory [1].
NORTHCOMVulns & exploitsPolicy & guidanceUnited States
2026-09-29 · Infosecurity Magazine · score 5.25
Microsoft Threat Intelligence warns that NeedyMantis threat actor from China has targeted organizations across a range of industries
PACOMMalware & toolingChina
2026-09-29 · The Hacker News · score 5.5
A group of academics from VUSec and Scuola Superiore Sant'Anna have disclosed details of a new Spectre CPU vulnerability variant that affects Just-In-Time (JIT) engines present in web browsers, language runtimes, and the operating system kernel, across multiple CPU vendors. The new Spectre-v2 variant has been codenamed Branch Target Reuse (BTR). "The key insight is that, while modern CPUs
Breach & leaked dataVulns & exploitsSupply chain
2026-09-29 · Malwarebytes Labs · score 5.5
A malicious file could trigger the vulnerability. Apple says it may already have been used against iPhone users.
NORTHCOMApps & devicesVulns & exploitsStandards & compliance
2026-09-29 · CyberScoop · score 6
The company said it found and patched a previously unknown critical vulnerability in one product during the weekend shutdown, and has no indication it was exploited.
NORTHCOMVulns & exploitsBreach & leaked dataRansomwareUnited States
2026-09-29 · The Register — security · score 6
Researchers find a way to recover stale indirect branch prediction entries
EUCOMVulns & exploitsBreach & leaked dataSupply chain
2026-09-29 · SpaceNews · via TJFSCC Daily · score 6.25
Commercial Defense Satcom Service Revenues to Surpass $22.6B by 2035
SPACECOMSpace & SATCOMvia TJFSCC Daily
2026-09-29 · CISA Cybersecurity Advisories · score 6.5
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to achieve remote code execution or cause a denial of service. The following versions of MikroTik RouterOS are affected: RouterOS <7.24 (CVE-2026-84411) CVSS Vendor Equipment Vulnerabilities v3 9.8 MikroTik MikroTik RouterOS Integer Underflow (Wrap or Wraparound) Background Critical Infrastructure Sectors: Communications, Information Technology Countries/Areas Deployed: Worldwide Company Headquarters Location: Latvia Vulnerabilities Expand All + CVE-2026-84411 The web management service in affected RouterOS versions contains an integer underflow in its HTTP request body handling that is reachable before authentication. This can be leveraged by an unauthenticated network attacker to achieve arbitrary code execution as root, or to cause a denial of service, using a single crafted request. View CVE Details Affected Products MikroTik RouterOS Vendor: MikroTik Product Version: MikroTik RouterOS: <7.24 Product Status: known_affected Remediations Vendor fix MikroTik recommends users update RouterOS to version 7.23 or later. The upgrade can be downloaded from the MikroTik website.…
EUCOMNORTHCOMVulns & exploitsCritical infrastructureSupply chain
2026-09-29 · Industrial Cyber · score 6.5
New analysis from Shieldworkz detailed the recent cyber breach involving Spain’s railway infrastructure manager Adif and train operator...
EUCOMBreach & leaked dataICS / OTAI & cyberInterlock
2026-09-29 · Dark Reading · score 7
Microsoft observed a China-based actor using a previously unidentified malware framework in targeted intrusions against telcos, universities, medical, and government-related organizations.
PACOMNORTHCOMMalware & toolingStandards & complianceChina
2026-09-29 · CyberScoop · score 7
Mandiant researchers said dozens of organizations have been impacted by attacks attributed to advanced and suspected state-sponsored threat groups. They expect more attacks to come.
EUCOMNORTHCOMVulns & exploitsAPT & espionageCloud & identity
2026-09-29 · The Register — security · score 7
Two questions remain: who is abusing the CVEs? And why did Citrix take so long to disclose?
NORTHCOMEUCOMVulns & exploitsMalware & toolingAPT & espionage
2026-09-29 · Industrial Cyber · score 7
Researchers from Nozomi Networks Labs identified 19 vulnerabilities in the Pepperl+Fuchs IO-Link Master ICE2-8IOL-K45P-RJ45 running EtherNet/IP firmware version...
NORTHCOMICS / OTVulns & exploitsPolicy & guidance
2026-09-29 · Yonhap News (English) · via TJFSCC Daily · score 7
YONGIN, South Korea, Sept. 30 (Yonhap) -- Twin pandas born at a South Korean amu...
PACOMAPT & espionageChinaROKvia TJFSCC Daily
2026-09-29 · Canadian Centre for Cyber Security · score 7.25
NORTHCOMVulns & exploitsApps & devicesStandards & complianceUnited States
2026-09-29 · Industrial Cyber · score 7.25
Australia’s Critical Infrastructure Security Centre is shifting toward a more formal enforcement posture in 2026-27, introducing tiered regulatory...
PACOMCritical infrastructureStandards & complianceBreach & leaked dataAustralia
2026-09-29 · CISA Cybersecurity Advisories · score 7.5
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to inject malformed messages which may lead to a denial-of-service condition. The following versions of Baicells Nova 430H are affected: Nova 430H eNodeB (model pBS3101SH) <=BaiBLQ_3.0.12 (CVE-2026-96274) CVSS Vendor Equipment Vulnerabilities v3 7.4 Baicells Technologies Baicells Nova 430H Uncaught Exception Background Critical Infrastructure Sectors: Communications, Information Technology Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-96274 In Baicells Nova 430H, an unauthenticated device within radio range can send a malformed uplink message during connection setup that contains an invalid NAS payload. Because the eNodeB does not properly validate this payload, it forwards the message to the core network, which can trigger a shutdown of the signaling association for the cell. This results in a temporary service disruption until the eNodeB and core network re-establish connectivity. View CVE Details Affected Products Baicells Nova 430H Vendor: Baicells Technologies Product Version: Baicells Technologies Nova 430H eNodeB…
NORTHCOMVulns & exploitsCritical infrastructureTelecom & cablesUnited States
2026-09-29 · CISA Cybersecurity Advisories · score 7.5
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-86950 Apple Multiple Products Out-of-Bounds Write Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability…
NORTHCOMVulns & exploitsPolicy & guidanceBreach & leaked dataUnited States
2026-09-29 · CISA Cybersecurity Advisories · score 7.75
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to access critical data or execute arbitrary code. The following versions of Toptech TMS7 and TopHAT are affected: TMS7 7.6.3 (CVE-2026-71379, CVE-2026-70356, CVE-2026-72510, CVE-2026-63713, CVE-2026-68954, CVE-2026-68068, CVE-2026-72507, CVE-2026-71302, CVE-2026-69662, CVE-2026-71189) TopHAT 7.6.3 (CVE-2026-71379, CVE-2026-70356, CVE-2026-72510, CVE-2026-63713, CVE-2026-68954, CVE-2026-68068, CVE-2026-72507, CVE-2026-71302, CVE-2026-69662, CVE-2026-71189) CVSS Vendor Equipment Vulnerabilities v3 10 Toptech Systems Toptech TMS7 and TopHAT Files or Directories Accessible to External Parties, Unrestricted Upload of File with Dangerous Type, Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), Session Fixation, Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection'), Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Background Critical Infrastructure Sectors: Energy, Chemical, Transportation Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities…
NORTHCOMVulns & exploitsPolicy & guidanceCritical infrastructureUnited States
2026-09-29 · The Hacker News · score 7.75
Russian state hackers known as Star Blizzard have been using fake event invitations to trick people into installing a backdoor on their Windows computers, according to Microsoft. The campaigns, aimed at people and organizations tied to Ukraine, have affected more than 100 organizations since January, mostly in the U.S. and U.K. At least one computer was infected, but the number of breached
EUCOMNORTHCOMAPT & espionageMalware & toolingBreach & leaked dataRussiaUnited States
2026-09-29 · SpaceWatch.Global · via Space Watch · score 7.75
Several United Airlines flights reported GPS interference near Los Angeles on 25 September, highlighting civil aviation's exposure to navigation disruption - uncommon in US airspace, but increasingly familiar in parts of Europe.
NORTHCOMSPACECOMSpace & SATCOMBreach & leaked dataUnited Statesvia Space Watch
2026-09-29 · CISA Cybersecurity Advisories · score 8
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to replace software and execute arbitrary code with root privileges. The following versions of Lantronix G520 Series Cellular Gateway are affected: G520 Series 2.6.0.4R6_stable (CVE-2026-84409, CVE-2026-91191) CVSS Vendor Equipment Vulnerabilities v3 7.5 Lantronix Lantronix G520 Series Cellular Gateway Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Verification of Cryptographic Signature Background Critical Infrastructure Sectors: Transportation Systems, Energy, Water and Wastewater Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-84409 The device's update mechanism retrieves metadata for software updates over an unencrypted HTTP connection and stores portions of that metadata for later use. A management interface subsequently returns this stored value in a JSON response, and the web interface responsible for displaying update information inserts that value directly into the page as HTML. This behavior allows attacker‑controlled metadata to be interpreted as script…
NORTHCOMVulns & exploitsCritical infrastructureICS / OTUnited States
2026-09-29 · AhnLab ASEC · score 8
Overview AhnLab monitored APT (Advanced Persistent Threat) attacks targeting entities in Korea using its own infrastructure. This report summarizes the types and statistics on domestic APT attacks identified during the month of August 2026. Trends of APT Attacks in South Korea Most of the APT attacks detected in South Korea were distributed via spear phishing […]
PACOMNORTHCOMAPT & espionageSocial engineeringROK
2026-09-29 · CyberScoop · score 8.5
Microsoft says the cyberespionage campaign has hit U.S. and U.K. targets, relying on sheer volume and requiring only a single victim interaction.
EUCOMNORTHCOMAPT & espionageSocial engineeringMalware & toolingRussiaUkraine
2026-09-29 · Microsoft Security / MSTIC · score 8.5
Since January 2026, Microsoft has observed Russian state threat actor Star Blizzard evolve their detection evasion capabilities through large-scale phishing campaigns, the use of accounts on compromised websites, and a novel malware delivery technique, tracked by Microsoft as “RedFlick”.
EUCOMNORTHCOMSocial engineeringAPT & espionageMalware & toolingRussiaUnited States
2026-09-29 · Inside Defense · via TJFSCC Daily · score 8.5
Sen. Tom Cotton (R-AR) is urging the Pentagon to evaluate its pathways for shipping military equipment after several critical F-35 Joint Strike Fighter components were diverted to Hong Kong this summer, according to a letter the lawmaker sent to Defense Secretary Pete Hegseth today. “We can’t afford for U.S. military equipment to fall into the hands of a foreign adversary because of vulnerabilities in commercial transportation,” wrote Cotton, who chairs the Senate Intelligence Committee. “Securing these supply chains is critical to ensuring that our warfighters around the world have access to the most advanced equipment and technology and to ensuring that our adversaries do not gain access to U.S. technology.” Earlier this summer, a shipment of sensitive and highly advanced F-35 technologies wound up in Hong Kong after being rerouted on its way to the U.S. from Australia for repairs, Politico reported this month . The equipment, which was being transported by a commercial intermediary of plane-maker Lockheed Martin, is still considered to be missing. The F-35 Joint Program Office did not immediately respond to questions from Inside Defense but told Politico it was aware of a…
PACOMNORTHCOMSupply chainVulns & exploitsUnited StatesAustraliavia TJFSCC Daily
2026-09-29 · Cisco Talos · score 9
This new proactive service joins the suite of retainer offerings to provide dedicated, intelligence-led hunting specifically for your organization’s most high-value IT assets.
NORTHCOMSPACECOMAPT & espionageSupply chainVulns & exploits
2026-09-29 · Nextgov/FCW — cybersecurity · score 9
“You know how to find us, and we know how to find you,” said Brett Leatherman, assistant director of the FBI’s Cyber Division. “I suggest you reach out first while the choice is still yours.”
NORTHCOMBreach & leaked dataAPT & espionageRansomwareShinyHuntersUnited States
2026-09-29 · CISA Cybersecurity Advisories · score 9.5
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to access sensitive information, access user accounts, execute OS-level commands, or take full control over the device. The following versions of Anjvision YSSD-RTMP-H5 are affected: YSSD-RTMP-H5 firmware 3.3.2.4_build_2024-12-26 (CVE-2026-100291, CVE-2026-100292, CVE-2026-100293, CVE-2026-100294, CVE-2026-100295, CVE-2026-100296, CVE-2026-100297, CVE-2026-100298, CVE-2026-100299) CVSS Vendor Equipment Vulnerabilities v3 9.8 Anjvision Anjvision YSSD-RTMP-H5 Initialization of a Resource with an Insecure Default, Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Improper Verification of Cryptographic Signature, Use of Hard-coded Credentials, Active Debug Code, Improper Check for Unusual or Exceptional Conditions, Server-Side Request Forgery (SSRF), Insufficiently Protected Credentials, Use of Weak Credentials Background Critical Infrastructure Sectors: Commercial Facilities Countries/Areas Deployed: Worldwide Company Headquarters Location: China Vulnerabilities Expand All + CVE-2026-100291 In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, several…
PACOMNORTHCOMVulns & exploitsSupply chainCritical infrastructureChina
2026-09-29 · CISA Cybersecurity Advisories · score 9.5
View CSAF Summary Successful exploitation of these vulnerabilities could allow attackers to access, modify, or delete sensitive user data and critical system files, potentially compromising the operation of the entire platform. The following versions of Viidure Dashcam Android Application are affected: Dashcam Android Application <=3.3.1.260403 (CVE-2026-94204, CVE-2026-96587) CVSS Vendor Equipment Vulnerabilities v3 10 Viidure Viidure Dashcam Android Application Incorrect Permission Assignment for Critical Resource, Use of Hard-coded Credentials Background Critical Infrastructure Sectors: Transportation Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: China Vulnerabilities Expand All + CVE-2026-94204 The central cloud storage backend for the entire dashcam platform is misconfigured with public‑read permissions, allowing unrestricted access to all stored objects. Because this bucket serves as shared storage for the platform, sensitive user records, live dashcam footage, application packages, and firmware files are exposed to anyone on the internet. View CVE Details Affected Products Viidure Dashcam Android Application Vendor: Viidure Product Version:…
PACOMApps & devicesVulns & exploitsSupply chainChina
2026-09-29 · The Register — security · score 10.75
RemoteThreat launches with $7M, 1,000 attack tools, and ambitions to equip enterprises and Uncle Sam for AI-speed operations
NORTHCOMSPACECOMAI & cyberStrategy & organizationAPT & espionageUnited States
2026-09-29 · Risky Business News · score 11.75
In other news: ShinyHunters member arrested in the Netherlands; Apple fixes iOS zero-day found by Meta; Citrix zero-days see mass exploitation within hours.
EUCOMCENTCOMVulns & exploitsBreach & leaked dataApps & devicesShinyHuntersRussiaIran
2026-09-28 · Canadian Centre for Cyber Security · score 3
Vulns & exploits
2026-09-28 · Canadian Centre for Cyber Security · score 3
Vulns & exploits
2026-09-28 · Canadian Centre for Cyber Security · score 3
Vulns & exploits
2026-09-28 · Canadian Centre for Cyber Security · score 3
Vulns & exploits
2026-09-28 · SecurityWeek · score 3.25
Cameron John Wagenius was sentenced to 70 months in prison for stealing information from the wireless carriers.
NORTHCOMTelecom & cables
2026-09-28 · Dark Reading · score 3.25
The "agentic threat actor" may have used exposed credentials to access resources and delete cloud-based storage, applications, and databases.
NORTHCOMCloud & identityAI & cyber
2026-09-28 · BleepingComputer · score 3.25
American tech company Kiteworks has lifted a precautionary advisory asking customers to shut down systems after patching a critical vulnerability. [...]
NORTHCOMVulns & exploitsUnited States
2026-09-28 · SecurityWeek · score 3.25
The malware framework uses a modular architecture and a custom executable file format for long-term persistence.
NORTHCOMMalware & toolingStandards & compliance
2026-09-28 · The Hacker News · score 3.75
The attacker who stole about $388 million from the cryptocurrency exchange Bitget gained access through a vulnerability in a third-party security product the exchange used, Bitget said on Monday. The attacker exploited the flaw to obtain high-level internal credentials and then, on September 24, used them to send fraudulent withdrawal commands to Bitget's wallet system. Exchanges keep most
NORTHCOMSupply chainVulns & exploits
2026-09-28 · CIS / MS-ISAC advisories · score 4
Multiple vulnerabilities have been discovered in NetScaler ADC and NetScaler Gateway, the most severe of which could allow for remote code execution. NetScaler ADC is a networking product that functions as an Application Delivery Controller (ADC), optimizing, securing, and ensuring reliable availability of applications for businesses. NetScaler Gateway is a secure remote access solution that provides users with single sign-on (SSO) access to applications and resources from any device. Successful exploitation of the most severe of these vulnerabilities could allow for remote code execution of commands on the system.
Vulns & exploitsCloud & identity
2026-09-28 · The Hacker News · score 4
Apple has released security updates to address a vulnerability in older versions of iOS, iPadOS, and macOS that it said may have been exploited in targeted attacks. The vulnerability, tracked as CVE-2026-86950, refers to an out-of-bounds write impacting the CoreGraphics component that could lead to arbitrary code execution when processing a maliciously crafted file. The iPhone maker said the
Vulns & exploitsApps & devices
2026-09-28 · Dark Reading · score 4
The botnet uses the open source Hermes Agent AI framework to execute commands via Telegram and steal AI API keys from exposed Docker hosts.
NORTHCOMMalware & toolingAI & cyberSupply chain
2026-09-28 · BleepingComputer · score 4
Apple released security updates to fix a zero-day vulnerability exploited in "extremely sophisticated" targeted attacks on iOS devices. [...]
Vulns & exploitsApps & devices
2026-09-28 · SecurityWeek · score 4
Apple released iOS and macOS updates to patch a zero-day vulnerability (CVE-2026-86950) reported by Meta’s product security team.
Vulns & exploitsApps & devices
2026-09-28 · UK NCSC · score 4.25
The NCSC is urging UK organisations to promptly mitigate vulnerabilities affecting Citrix NetScaler ADC and Gateway, two of which are being actively exploited.
EUCOMVulns & exploitsUK
2026-09-28 · The Hacker News · score 4.25
Cybersecurity researchers have disclosed details of a new botnet malware called Carbonato that's targeting exposed Docker daemons to deploy an open-source artificial intelligence (AI) agent framework called Hermes Agent. "The implant installs the framework unchanged, then overwrites its SOUL.md persona file," ThreatDown said. "The 39-line prompt directs it to execute tasks received through
Malware & toolingApps & devicesAI & cyber
2026-09-28 · Canadian Centre for Cyber Security · score 4.25
Vulns & exploitsCloud & identity
2026-09-28 · The Record (Recorded Future) · score 4.25
A vulnerability in a popular line of products from Oracle is being used in a new campaign by the prolific ShinyHunters hacking group, which recently claimed credit for an attack on the FBI’s jobs site.
NORTHCOMVulns & exploitsShinyHuntersUnited States
2026-09-28 · Rapid7 blog · score 4.5
Overview On September 27, 2026, Citrix disclosed eight new vulnerabilities affecting NetScaler ADC and NetScaler Gateway, including two critical remote code execution (RCE) vulnerabilities: CVE-2026-88771 and CVE-2026-88772 . Both of these RCE vulnerabilities carry a critical CVSSv4 score of 9.5, and both have been confirmed as being actively exploited in the wild as zero-days prior to the vendor disclosure . CVE-2026-88771 affects vulnerable NetScaler deployments in their default configuration, with no additional product features required. The vendor has also indicated that the attack complexity for exploiting CVE-2026-88771 is low, meaning reliable RCE is likely against all vulnerable NetScaler appliances regardless of their configuration. This is especially concerning due to the prevalence of NetScaler appliances. CVE-2026-88772 is a memory corruption vulnerability and requires the DTLS feature to be enabled on the appliance. The vendor has indicated that the attack complexity is high, meaning achieving reliable exploitation may be more difficult for an attacker than that of CVE-2026-88771. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) reports active…
NORTHCOMVulns & exploitsSupply chainUnited States
2026-09-28 · The Record (Recorded Future) · score 4.5
Incident responders began warning of potential vulnerabilities in NetScaler Gateway products on Saturday before cybersecurity agencies in the Netherlands, U.S. and U.K. released advisories on Sunday confirming vulnerabilities. Citrix itself confirmed eight new vulnerabilities.
EUCOMNORTHCOMVulns & exploitsUKUnited States
2026-09-28 · Dark Reading · score 4.5
A high-severity zero-day vulnerability affects the TDengine time-series database used across industrial, IoT, energy, and automotive environments.
NORTHCOMVulns & exploitsApps & devices
2026-09-28 · SecurityWeek · score 4.75
The extortion group has modified its exploit in new attacks targeting the PeopleSoft vulnerability CVE-2026-35273.
Vulns & exploitsRansomwareShinyHunters
2026-09-28 · BleepingComputer · score 5.25
Keio Corporation (Keio), a major private railway operator in Japan, said its network was hit by a ransomware attack over the weekend, disrupting some of its business systems. [...]
PACOMRansomwareJapan
2026-09-28 · SANS Internet Storm Center · score 5.25
Apple today released patches for all of its operating systems. However, only patches for older branches include a security fix. The vulnerability being addressed in iOS 26, macOS 26 and macOS 15 is already being exploited. iOS and macOS 27 are not affected. Today&#;x26;#;39;s update for the current "27" branch does not address security issues, but fixes some functional issues that got caught after the release two weeks ago. A 27.1 version was also expected to support the new foldable iPhone and will likely include specific features geared to the soon to be available device.
NORTHCOMVulns & exploitsApps & devicesUnited States
2026-09-28 · Canadian Centre for Cyber Security · score 5.5
NORTHCOMVulns & exploitsStandards & complianceUnited States
2026-09-28 · CERT/CC Vulnerability Notes (Carnegie Mellon SEI) · score 5.5
Overview Authlib (versions up to and including 1.7.2) contain a signature‑verification bypass in the JSON Web Signature (JWS) general JSON serialization handling. The JsonWebSignature.deserialize_json() function accepts a JWS object with an empty "signatures" array and treats the payload as successfully verified, allowing attackers to supply arbitrary forged content without possessing any key material. Description Authlib is a Python library that provides tools for implementing OAuth, OpenID Connect, JWT/JWS/JWE (JSON Web Token / JSON Web Signature / JSON Web Encryption), and other modern authentication and authorization standards. It’s widely used in web applications and microservices to handle token creation, cryptographic validation, and secure communication. As discussed in CVE-2026-96760 , a security flaw in Authlib’s handling of JSON Web Signatures (JWS) makes it possible for an attacker to skip signature verification completely. Normally, a JWS should include at least one valid signature to prove the data hasn’t been tampered with. However, Authlib’s deserialize_json() function mistakenly accepts JWS objects even when the "signatures" section is an empty list. Because the…
NORTHCOMVulns & exploitsCloud & identitySupply chain
2026-09-28 · The Hacker News · score 6
Hackers have used a malware family called NeedyMantis to maintain long-term access to networks they had already breached, Microsoft said in a technical analysis. The malware has been seen in a small number of targeted intrusions at telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors. Its use goes back to at least
NORTHCOMBreach & leaked dataMalware & toolingTelecom & cables
2026-09-28 · CyberScoop · score 6
The vendor’s products are a common, recurring target for attackers, yet the official warning for some Citrix NetScaler customers was too late.
NORTHCOMVulns & exploitsMalware & toolingPolicy & guidance
2026-09-28 · Payload · via TJFSCC Daily · score 6.25
“Meridian will carry forward the satcom infrastructure business… SpinLaunch will continue to build on its vision for a lower-cost approach to launch, with further applications in hypersonics to support the Golden Dome program and in the lunar economy," Meridian Space CEO Massimiliano Ladovaz told Payload.
SPACECOMSpace & SATCOMvia TJFSCC Daily
2026-09-28 · CyberScoop · score 6.5
Cybercrime experts are stunned as ShinyHunters risks agent safety and intense federal heat in a bizarre attempt to force the retraction of an agency advisory.
NORTHCOMRansomwareBreach & leaked dataCloud & identityShinyHuntersUnited States
2026-09-28 · The Record (Recorded Future) · score 6.5
A former soldier in the U.S. Army was sentenced to more than five years in federal prison after pleading guilty to hacking into several telecommunications companies and leaking sensitive records.
NORTHCOMTelecom & cablesBreach & leaked dataUnited States
2026-09-28 · Krebs on Security · score 9
Authorities in the Netherlands have arrested a 23-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters. In the days immediately following the suspect's arrest, remaining ShinyHunters members dramatically escalated their attacks, stealing highly sensitive data from the FBI and extorting the Russian ransomware group Cl0p.
EUCOMNORTHCOMRansomwareBreach & leaked dataVulns & exploitsShinyHuntersCl0pRussiaUnited States
2026-09-28 · Microsoft Security / MSTIC · score 9.5
Microsoft Threat Intelligence identified NeedyMantis, a modular post-compromise malware framework used in targeted intrusions that combines custom loaders, encrypted archives, and extensible components to maintain long-term access and support follow-on operations.
NORTHCOMPACOMMalware & toolingSupply chainAPT & espionageChina
2026-09-28 · Nextgov/FCW — cybersecurity · score 9.5
The group’s new statement — which called the incident a “marketing campaign" — follows reports that the stolen material includes medical records and details about employees working in sensitive intelligence roles.
NORTHCOMPACOMBreach & leaked dataStandards & complianceShinyHuntersUnited StatesChina
2026-09-28 · SpaceWatch.Global · via Space Watch · score 9.5
Swedish Space Corporation has completed an upgrade of its optical ground station in Western Australia, bringing the facility into operational service with support for both Space Development Agency and Consultative Committee for Space Data Systems optical communications standards.
SPACECOMPACOMSpace & SATCOMAustraliavia Space Watch
2026-09-28 · The Register — security · score 11
Active-duty campaign targeted at least ten organizations and sought $1 million in ransom payments
NORTHCOMPACOMTelecom & cablesCloud & identityRansomwareROKUnited States
2026-09-28 · Check Point Research · score 11.5
For the latest discoveries in cyber research for the week of 28th September, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES The FBI has confirmed unauthorized activity affecting FBIjobs.gov after the ShinyHunters group defaced the website. The group claimed to have stolen employee and applicant information and shared samples of purported FBI personnel […]
PACOMNORTHCOMVulns & exploitsAI & cyberBreach & leaked dataShinyHuntersNorth KoreaAustralia
2026-09-27 · BleepingComputer · score 2.5
Two unpatched Citrix NetScaler ADC and Gateway RCE zero-days are being exploited, according to watchTowr; Citrix has not confirmed them and patches are expected this week.
NetScaler Gateway fronts remote access for many partners.
Recommend confirming no internet-facing NetScaler in command or partner paths.
Vulns & exploitsAI-curated
2026-09-27 · SANS Internet Storm Center · score 3
Wireshark release 4.6.9 fixes 19 vulnerabilities and 16 bugs.
NORTHCOMVulns & exploitsUnited States
2026-09-27 · AhnLab ASEC · score 3
The AhnLab SEcurity intelligence Center (ASEC) has identified two vulnerability attack cases that exploited a remote code execution vulnerability (CVE-2019-18935) targeting unpatched Telerik UI for ASP.NET AJAX servers. In the first incident, after exploiting the vulnerability, the attacker executed a reverse shell, attempted to perform privilege escalation, and installed a web shell; in the second […]
Vulns & exploitsMalware & tooling
2026-09-27 · BleepingComputer · score 3.5
Cloudflare has fixed a vulnerability in Containers and Sandboxes that allowed customers with a Workers Paid account to recover residual data from other customers' containers on the same physical host. [...]
Breach & leaked dataVulns & exploits
2026-09-27 · BleepingComputer · score 3.5
The Cybersecurity and Infrastructure Security Agency (CISA) has ordered U.S. government agencies over the weekend to secure their systems against attacks exploiting two critical Citrix NetScaler vulnerabilities. [...]
NORTHCOMVulns & exploitsUnited States
2026-09-27 · The Hacker News · score 3.5
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Sunday added two critical Citrix NetScaler ADC and Gateway flaws to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation. The vulnerabilities are listed below - CVE-2026-88771 (CVSS score: 9.5) - An improper input validation vulnerability that could allow an unauthenticated attacker to
NORTHCOMVulns & exploitsUnited States
2026-09-27 · CISA Cybersecurity Advisories · score 5.25
Citrix patched NetScaler zero-days CVE-2026-88771 and -88772 (in KEV) on 27 Sep. According to Mandiant, exploitation began 3 Sep and hit dozens of government, finance and telecom organizations.
NetScaler fronts partner remote access; intrusions predate the patch.
Recommend checking NetScaler for compromise, not only patch status.
CYBERCOMVulns & exploitsUnited StatesUKAI-curated
2026-09-27 · BleepingComputer · score 5.5
A former U.S. Army soldier has been sentenced to 70 months in prison for hacking and extorting at least 10 U.S. technology and telecommunications companies between April 2023 and December 2024. [...]
NORTHCOMTelecom & cablesUnited States
2026-09-27 · UPI (Defense) · via TJFSCC Daily · score 6.5
Zoo Atlanta on Sunday morning welcomed two giant pandas from China as part of an agreement between Beijing and Washington.
PACOMAPT & espionageChinaUnited Statesvia TJFSCC Daily
2026-09-27 · New York Times (Asia-Pacific) · via TJFSCC Daily · score 7
A male named Ping Ping and a female named Fu Shuang landed on Sunday, days after China’s leader said he would dispatch “envoys of friendship” to the United States.
PACOMNORTHCOMAPT & espionageChinaUnited Statesvia TJFSCC Daily
2026-09-27 · Canadian Centre for Cyber Security · score 7.25
NORTHCOMVulns & exploitsPolicy & guidanceSupply chainCanada
2026-09-27 · Risky Business News · score 7.25
In other news: OpenAI agents probed dozens of organizations; fraudsters use AI to scam €95m from an Italian bank; Bitget hacked for $350m.
NORTHCOMVulns & exploitsScams & fraudSupply chainScattered SpiderUnited States
2026-09-27 · CISA Cybersecurity Advisories · score 7.5
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-88771 Citrix NetScaler Improper Input Validation Vulnerability CVE-2026-88772 Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was…
NORTHCOMVulns & exploitsPolicy & guidanceBreach & leaked dataUnited States
2026-09-27 · South China Morning Post (China) · via TJFSCC Daily · score 7.5
Two giant pandas have arrived in Atlanta to take up residency at the southern US city’s zoo. The pandas, male Ping Ping and female Fu Shuang, left Chengdu in China’s southwest on Sunday, within days of Chinese President Xi Jinping wrapping up his three-day state visit to the United States. During the visit, Xi said the pandas would arrive “in a few days”. Ping Ping and Fu Shuang, whose names mean peace and double blessings, arrived at Atlanta International Airport on a chartered flight, state...
NORTHCOMPACOMAPT & espionageChinaUnited Statesvia TJFSCC Daily
2026-09-27 · The Guardian (Australia) · via TJFSCC Daily · score 8.25
Federal cabinet will discuss the OpenAI breach on Monday as the AI giant pauses testing of latest models amid fallout Follow our Australia news live blog for latest updates Get our new political email , free app or daily news podcast Ageing computer systems used throughout Australia’s government and large sections of the economy are easily exploited by AI agents, increasing the risk that sensitive information could be compromised, Australia’s former chief UN cyber negotiator has warned. As the government urgently undertakes a forensic investigation into a rogue OpenAI agent accessing Medicare data, the AI expert and Tech Policy Design Institute executive director, Johanna Weaver, said huge vulnerabilities existed across older IT systems. Sign up for Guardian Australia’s Politics, really newsletter here
PACOMNORTHCOMAI & cyberVulns & exploitsBreach & leaked dataAustraliaUnited Statesvia TJFSCC Daily
2026-09-27 · The Guardian (World) · via TJFSCC Daily · score 8.75
Pandas departed Chengdu for their new homes in Georgia as part of agreement between Chinese and US governments Two giant pandas departed Chengdu in south-western China early on Sunday for their new homes in Atlanta , Georgia, as part of an agreement between the Chinese and US governments. While in Washington DC for a three - day summit with Donald Trump , Chinese president Xi Jinping announced that the pandas would arrive in Atlanta in the coming days. The loan of the pandas to the Atlanta zoo was one of the few concrete outcomes to come out of Xi’s state visit with the US president, which saw expressions of goodwill between the leaders, but no fixes to any of the longstanding differences between the two countries.
PACOMEUCOMAPT & espionageScattered SpiderChinaUnited Statesvia TJFSCC Daily
2026-09-27 · Industrial Cyber · score 9.5
New data from NCC Group identified that global ransomware activity reached a new 2026 high in August, with...
NORTHCOMEUCOMRansomwareAPT & espionageBreach & leaked dataQilinRussiaUnited States
2026-09-27 · Malwarebytes Labs · score 9.5
A list of topics we covered in the week of September 21 to September 27 of 2026
NORTHCOMPACOMMalware & toolingSocial engineeringBreach & leaked dataShinyHuntersAustraliaUnited States
2026-09-27 · Industrial Cyber · score 10.25
Rapid expansion of satellite communications is creating new cybersecurity exposure as more than 18,000 active satellites orbit Earth...
SPACECOMCENTCOMSpace & SATCOMCritical infrastructureApps & devices
2026-09-26 · The Hacker News · score 4.25
Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors globally. The ShinyHunters-linked activity involves the weaponization of CVE-2026-35273 (CVSS score: 9.8), a critical security flaw that could result in unauthenticated remote code execution. The vulnerability was first exploited as a zero-day
Vulns & exploitsMalware & toolingShinyHunters
2026-09-26 · SecurityWeek · score 4.5
CISA added CVE-2026-65660 to its KEV catalog, giving federal agencies a patching deadline of September 28.
NORTHCOMVulns & exploitsCloud & identityUnited States
2026-09-26 · BleepingComputer · score 5.25
The ShinyHunters extortion gang is using a URL-encoding trick to bypass web application firewall rules that mitigate the Oracle PeopleSoft CVE-2026-35273 flaw, allowing the threat actors to resume widespread exploitation of a flaw on vulnerable servers. [...]
NORTHCOMVulns & exploitsRansomwareShinyHunters
2026-09-26 · The Straits Times (Asia) · via TJFSCC Daily · score 6.5
China loans pandas out as part of a “panda diplomacy” programme to foster foreign ties.
PACOMNORTHCOMAPT & espionageChinavia TJFSCC Daily
2026-09-26 · The Japan Times · via TJFSCC Daily · score 7
The pandas' transfer had been already agreed but the departure was announced Thursday during Chinese leader Xi Jinping's visit to Washington.
PACOMNORTHCOMAPT & espionageChinaUnited Statesvia TJFSCC Daily
2026-09-26 · CISA Known Exploited Vulnerabilities · score 10.25
Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability. Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for remote code execution or denial of service Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Due 2026-09-30.
NORTHCOMVulns & exploitsPolicy & guidanceBreach & leaked dataUnited StatesKEV
2026-09-26 · CISA Known Exploited Vulnerabilities · score 10.25
Citrix NetScaler Improper Input Validation Vulnerability. Citrix NetScaler ADC and NetScaler Gateway contain an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Due 2026-09-30.
NORTHCOMVulns & exploitsPolicy & guidanceBreach & leaked dataUnited StatesKEV
2026-09-25 · BleepingComputer · score 2.5
Secure file-sharing software company Kiteworks is urging customers worldwide to temporarily shut down their servers on Saturday for a six-hour window after receiving threat intelligence warning of a potentially imminent cyberattack. [...]
Vulns & exploits
2026-09-25 · Canadian Centre for Cyber Security · score 3
Vulns & exploits
2026-09-25 · The Hacker News · score 3
The Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability is being actively exploited in the wild. The vulnerability in question is CVE-2026-48842 (CVSS score: 8.1), a pre-authentication SQL injection in the virtuser_query plugin of Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1. The issue stems from a preg_replace() backslash
NORTHCOMVulns & exploitsCanada
2026-09-25 · SecurityWeek · score 3
Homeland Security Secretary Markwayne Mullin tasked CISA with developing the plan in July.
NORTHCOMVulns & exploitsUnited States
2026-09-25 · Canadian Centre for Cyber Security · score 3
Vulns & exploits
2026-09-25 · The Hacker News · score 3.5
Cybersecurity researchers have flagged a new version of PamStealer that ensures that the main payload can only be recovered using a server-side decryption chain. The latest artifacts, per Jamf Threat Labs, continue to rely on the same JavaScript for Automation (JXA) dropper mechanism, but modify the lure and the delivery method. "Where earlier variants embedded their payload key material
NORTHCOMMalware & toolingSocial engineering
2026-09-25 · NPR World · via TJFSCC Daily · score 4
The visit comes at an important time for both men.
APT & espionageChinavia TJFSCC Daily
2026-09-25 · The Diplomat · via TJFSCC Daily · score 4
The visit's outcomes are thin: a small extension of the trade truce and two pandas.
APT & espionageChinavia TJFSCC Daily
2026-09-25 · DefenseScoop · score 4.5
The recurring joint military tests refine rapidly maturing technologies that can sense, monitor, and mitigate rogue and hostile drones.
NORTHCOMCritical infrastructureUnited States
2026-09-25 · BleepingComputer · score 4.5
The Cybersecurity and Infrastructure Security Agency (CISA) warns that hackers are exploiting a critical authentication bypass vulnerability (CVE-2026-5430) affecting multiple products from enterprise software provider WSO2. [...]
NORTHCOMVulns & exploitsCloud & identityUnited States
2026-09-25 · The Hacker News · score 4.5
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added two security flaws impacting Microsoft SharePoint and Mikrotik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilities in question are as follows - CVE-2026-65660 (CVSS score: 8.8) - A code injection vulnerability in Microsoft Office SharePoint
NORTHCOMVulns & exploitsCloud & identityUnited States
2026-09-25 · Microsoft Security / MSTIC · score 5
Microsoft details JADEPUFFER-linked Azure reconnaissance, resource deletion, and credential access using compromised service principals, identifying the activity as associated with Storm-3168 and providing guidance for defenders.
NORTHCOMCloud & identityAI & cyberRansomware
2026-09-25 · Inside GNSS · via Space Watch · score 5
GNSS receivers employ new technology to deliver comprehensive anti-jamming and anti-spoofing capabilities, better performance and future-ready support for low-earth orbit constellations to OEM...
SPACECOMSpace & SATCOMvia Space Watch
2026-09-25 · SANS Internet Storm Center · score 5.25
Introduction
NORTHCOMMalware & toolingSocial engineeringRansomware
2026-09-25 · SecurityWeek · score 5.75
Noteworthy stories that might have slipped under the radar: BragJack attack against browser AI assistants, TDengine flaw threatens industrial telemetry uptime, Ubuntu update overhaul.
Breach & leaked dataCritical infrastructureRansomwareCl0p
2026-09-25 · CERT/CC Vulnerability Notes (Carnegie Mellon SEI) · score 5.75
Overview Three cross-site scripting (XSS) vulnerabilities identified in Readwise Reader for Android version 8.7.2 are disclosed. An attacker with the ability to craft malicious documents or metadata can exploit these vulnerabilities by supplying poisoned content that bypasses sanitization. Successful exploitation could allow the attacker to execute arbitrary JavaScript within the application's WebView context and compromise the confidentiality and integrity of user data, including access to stored documents, credentials, and session tokens. Description Readwise Reader from Readwise is designed to provide a unified read-it-later service that helps individuals collect and organize articles, newsletters, videos, and other content of interest into a single reading interface. It is available on multiple platforms including Android and can synchronize content across devices. CVE-2026-18311 : A stored cross-site scripting (XSS) vulnerability in the header rendering component in Readwise Reader for Android version 8.7.2 allows remote attackers to execute arbitrary JavaScript via crafted document metadata fields. The header rendering component is impacted due to insufficient HTML escaping…
Vulns & exploitsApps & devicesSupply chain
2026-09-25 · Canadian Centre for Cyber Security · score 6
PACOMVulns & exploitsAustralia
2026-09-25 · CIS / MS-ISAC advisories · score 6.25
Multiple vulnerabilities have been discovered in ServiceNow's AI Platform, the most severe of which could allow for unauthorized access. The ServiceNow AI Platform is a unified, cloud-based foundation that integrates artificial intelligence, data, and workflow automation to execute business operations across entire enterprises. Successful exploitation of the most severe of these vulnerabilities could allow for unauthorized access.
Vulns & exploitsPolicy & guidanceCloud & identity
2026-09-25 · The Register — security · score 6.5
Data theft and extortion biz, that is
NORTHCOMBreach & leaked dataSupply chainVulns & exploitsShinyHuntersUnited States
2026-09-25 · New York Times (Asia-Pacific) · via TJFSCC Daily · score 6.5
Easing tensions with Washington gives Beijing room to tackle economic troubles at home while reducing its vulnerability to American pressure.
PACOMNORTHCOMVulns & exploitsChinaUnited Statesvia TJFSCC Daily
2026-09-25 · BleepingComputer · score 7
The Clop ransomware gang has moved its data leak site to a new Tor address after confirming its previous server was compromised and defaced through an unpatched Grav CMS flaw that BleepingComputer has learned is an unauthenticated path traversal vulnerability. [...]
NORTHCOMRansomwareBreach & leaked dataVulns & exploitsCl0pShinyHunters
2026-09-25 · The Guardian (World) · via TJFSCC Daily · score 7
While US president hailed visit as ‘great’, almost nothing of substance was achieved on resolving thorny issues Key takeaways from the Trump-Xi summit in Washington If the Beijing meeting between Donald Trump and Xi Jinping in May was the “ stalemate summit ”, the second round of talks between the presidents of the US and China this week seemed to give up entirely on the idea of breakthroughs. Instead, it was described as a celebration of “ diplotainment ” rather than diplomacy, where pomp prevailed over progress and where one of the main outcomes was the news that two giant pandas would soon be sent from China to Atlanta zoo.
PACOMNORTHCOMAPT & espionageChinaUnited Statesvia TJFSCC Daily
2026-09-25 · New York Times (Asia-Pacific) · via TJFSCC Daily · score 7
Xi Jinping, China’s leader, said two pandas would arrive soon at Zoo Atlanta. Panda diplomacy has been a cornerstone of U.S.-China relations.
PACOMNORTHCOMAPT & espionageChinaUnited Statesvia TJFSCC Daily
2026-09-25 · New York Times (Asia-Pacific) · via TJFSCC Daily · score 7
President Trump pressed his personal brand of diplomacy as President Xi Jinping of China made his first trip to the White House in more than a decade.
PACOMNORTHCOMAPT & espionageChinaUnited Statesvia TJFSCC Daily
2026-09-25 · CISA Cybersecurity Advisories · score 7.25
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-87902 WordPress Core Remote File Inclusion Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability…
NORTHCOMVulns & exploitsPolicy & guidanceBreach & leaked dataUnited States
2026-09-25 · CISA Cybersecurity Advisories · score 7.5
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-65660 Microsoft SharePoint Code Injection Vulnerability CVE-2026-67279 Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. While BOD 26-04 applies only…
NORTHCOMVulns & exploitsPolicy & guidanceBreach & leaked dataUnited States
2026-09-25 · Inside Defense · via TJFSCC Daily · score 7.5
Pentagon leaders fan out on Capitol Hill as FY-27 funding picture fractures Pentagon estimates $43.6B in Iran war costs, replacement needs Sustaining legacy production, new entrants key to defense industry success, official says GAO recommends annual SIOP status update, citing lack of oversight requirements Navy advances W93 nuclear warhead to EMD phase Navy selects captain to serve as next chief of information Navy RCO seeking maritime awareness tech via 'Disruptor Days' DIU seeking investors to fund facility clearances for C-UXS maritime tech providers Industry warns DOD cost transparency push could undermine plans for defense expansion Navy announces new unmanned Warfighting Development Center DOD will undertake three-tiered strategy on MOSA DOD invites companies to Drone Dominance event focused on reusable bombers Navy plans to issue SIOP solicitation this month Honeywell debuts upgrade for F-35 cooling system ISC2 highlights challenges facing defense contractors under CMMC pause Newsletter Type: Inside the Navy
CENTCOMICS / OTSupply chainStandards & complianceIranUnited Statesvia TJFSCC Daily
2026-09-25 · The Hacker News · score 8.25
Cryptocurrency exchange Bitget said suspected North Korean threat actors have stolen $351.6 million from its hot and warm wallets. "At 18:31 UTC on September 24, 2026, Bitget's security systems identified unauthorized transfers involving a limited number of hot wallets," BitGet said in a post shared on X. "Bitget's cold wallets and the overwhelming majority of platform assets remain
PACOMDPRK & crypto theftPolicy & guidanceNorth Korea
2026-09-25 · CyberScoop · score 9
Cameron Wagenius was involved in some of the most high-profile attacks of 2024 while on active duty.
NORTHCOMEUCOMTelecom & cablesCloud & identityBreach & leaked dataUnited StatesRussia
2026-09-25 · Krebs on Security · score 12.25
A U.S. Army soldier who pleaded guilty to hacking into multiple telecommunications companies and stealing mobile call and text metadata for more than 100 million AT&T customers in 2024 was sentenced to 70 months in federal prison today and ordered to pay nearly $300,000 in restitution to victims.
NORTHCOMCYBERCOMTelecom & cablesRansomwareBreach & leaked dataUnited StatesROK
2026-09-24 · Canadian Centre for Cyber Security · score 3
Vulns & exploits
2026-09-24 · BleepingComputer · score 3
A high-severity Roundcube Webmail vulnerability patched in May is now being actively exploited in attacks, according to the Canadian Centre for Cyber Security. [...]
NORTHCOMVulns & exploitsCanada
2026-09-24 · SecurityWeek · score 3
The vulnerabilities, tracked as CVE-2026-28324 and CVE-2026-28325, can be exploited without authentication.
Vulns & exploitsSupply chain
2026-09-24 · CIS / MS-ISAC advisories · score 3.25
Multiple vulnerabilities have been discovered in Google Chrome, the most severe of which could allow for arbitrary code execution. Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution in the context of the logged on user. Depending on the privileges associated with the user an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.
Vulns & exploits
2026-09-24 · SecurityWeek · score 4
A threat actor is using three AI harnesses for vulnerability research, exploitation, and attack orchestration.
NORTHCOMAI & cyberVulns & exploits
2026-09-24 · BleepingComputer · score 4
A new botnet malware called Carbonato is targeting insecure hosts running Docker daemons to install the Hermes Agent AI framework and take control. [...]
NORTHCOMAI & cyberMalware & toolingStandards & compliance
2026-09-24 · The Hacker News · score 4.25
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical security flaws impacting WSO2 and Adobe Commerce and Magento to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The vulnerabilities are listed below - CVE-2026-5430 (CVS score: 9.8) - A path traversal vulnerability in WSO2 API Control Plane,
NORTHCOMVulns & exploitsStandards & complianceUnited States
2026-09-24 · BleepingComputer · score 4.75
​The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies on Wednesday that ransomware gangs are now also exploiting a critical JetBrains TeamCity vulnerability patched in July. [...]
NORTHCOMRansomwareVulns & exploitsUnited States
2026-09-24 · Cisco Talos · score 5
In this week’s newsletter Martin muses over a very suspicious elicitation over social media and the true value of trust within the cyber ecosystem. Hubris might be the real vulnerability that the cyber industry must worry about.
Social engineeringVulns & exploitsSupply chain
2026-09-24 · Recorded Future — Insikt · score 5.75
Learn how ransomware threat intelligence empowers your team to actively follow adversary infrastructure, monitor dark web chatter and prevent attacks.
NORTHCOMRansomwareMalware & toolingBreach & leaked data
2026-09-24 · The Register — security · score 6
Gemini 3.8 Flash Cyber and Wiz's Red Agent team up to protect hospitals, public transit, and tech
NORTHCOMSPACECOMAI & cyberSupply chainCloud & identity
2026-09-24 · CISA Cybersecurity Advisories · score 6
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to bypass authentication controls, gain unauthorized access to sensitive data and privileged device functionality, modify device configuration, disrupt device operation. The following versions of Botslab G980H Dashcams are affected: G980H dash cam series 30010_QHG980HN5294SysFW+ (CVE-2026-84399, CVE-2026-82566, CVE-2026-85496, CVE-2026-77967, CVE-2026-88761, CVE-2026-82716, CVE-2026-84403, CVE-2026-75558, CVE-2026-81630, CVE-2026-87118, CVE-2026-82708, CVE-2026-79959, CVE-2026-82585) G980H dash cam series 58_QHG980HMCN5291SysFW+ (CVE-2026-84399, CVE-2026-82566, CVE-2026-85496, CVE-2026-77967, CVE-2026-88761, CVE-2026-88956, CVE-2026-82716, CVE-2026-84403, CVE-2026-75558, CVE-2026-81630, CVE-2026-87118, CVE-2026-82708, CVE-2026-82585) CVSS Vendor Equipment Vulnerabilities v3 8.8 Botslab Botslab G980H Dashcams Incorrect Authorization, Insufficient Session Expiration, Generation of Predictable Numbers or Identifiers, Authentication Bypass by Capture-replay, Use of Weak Credentials, Missing Authentication for Critical Function, Insertion of Sensitive Information into Log File, Use of Hard-coded…
Vulns & exploitsPolicy & guidanceSupply chain
2026-09-24 · Canadian Centre for Cyber Security · score 6.25
NORTHCOMVulns & exploitsCloud & identityBreach & leaked dataCanada
2026-09-24 · SecurityWeek · score 6.5
Revision 4 of NIST’s operational technology security guide is open for public comments until November 30.
NORTHCOMICS / OTPolicy & guidanceStandards & complianceUnited States
2026-09-24 · Rapid7 blog · score 6.75
Business Email Compromise (BEC) operates on a familiar playbook. Threat actors breach a mailbox, silently monitor operations, map approval chains, and ultimately exploit that access to divert funds or exfiltrate sensitive assets. This dynamic is central to our analysis as we kick off a series around Rapid7's collaborative research with Zimbra; upcoming installments will explore technical details and broader findings based within the Zimbra Collaboration Suite. Our investigation disrupted the traditional BEC model in unexpected ways. We uncovered over 50 vulnerabilities, and found that several allow attackers not just to observe environments, but to actively rewrite them by impersonating senders without credentials, controlling inbox visibility, and altering shared documents and calendars. Business Email Compromise in action: Digital abuse of trust None of this is theoretical for Zimbra. But don’t take my word for it, just ask Russia . CISA keeps putting Zimbra bugs into the Known Exploited Vulnerabilities catalog , and the last three years make the point on their own: CVE-2024-45519 , command injection in the postjournal service, unauthenticated command execution. Proofpoint saw…
EUCOMNORTHCOMSocial engineeringVulns & exploitsBreach & leaked dataRussiaUnited States
2026-09-24 · The Guardian (Australia) · via TJFSCC Daily · score 6.75
This blog is now closed Get our breaking news email , free app or daily news podcast AI hack of Medicare exposes Australia’s vulnerabilities Technology experts have warned revelations an artificial intelligence agent hacked Medicare’s internal systems will not be the only dangerous breach of government data and have called for Australia to boost its protections against the growing risk. Frontier AI now has capability to expose those vulnerabilities at a rate quicker than we can keep up, quicker than we can patch them. What if it was a less benign breach? What if it was a less benign actor? Let’s face it, clearly, Services Australia’s cybersecurity is woefully inadequate. I mean the irony here is that you actually need AI to fight AI. This should hasten, if anything, our move over in the US to less finger wagging and Trump one-upmanship, and more about embracing these AI companies and bringing them here so that we can have frontier models providing sovereign capability to Australia. Because AI is going to happen.
PACOMNORTHCOMBreach & leaked dataVulns & exploitsAustraliavia TJFSCC Daily
2026-09-24 · CISA ICS Advisories · score 7
View CSAF Summary This advisory is revoked. Re-investigation confirmed the reported behavior is expected platform configuration and does not expose the protected attribute. The following versions of Siemens Mendix Runtime are affected: Siemens Mendix Runtime vers:all/* (CVE-2026-7891) CVSS Vendor Equipment Vulnerabilities v3 9.1 Siemens Siemens Mendix Runtime Insecure Inherited Permissions Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-7891 This CVE has been retracted. Re-investigation confirmed the reported behavior is expected platform configuration and does not expose the protected application-specific attribute. View CVE Details Affected Products Siemens Mendix Runtime (Update A) Vendor: Siemens Product Version: Siemens Siemens Mendix Runtime: vers:all/* Product Status: not_affected Remediations Mitigation Vulnerability is rejected as re-investigation confirmed the reported behavior is expected platform configuration and does not expose the protected application-specific attribute (Vulnerable Code Not Present). Mitigation As a general security…
EUCOMVulns & exploitsICS / OTCritical infrastructure
2026-09-24 · Canadian Centre for Cyber Security · score 7.25
NORTHCOMCloud & identityVulns & exploitsApps & devicesUnited States
2026-09-24 · SecurityWeek · score 7.25
Australia disclosed that an OpenAI agent gained unauthorized access to non-public government information.
PACOMVulns & exploitsPolicy & guidanceAustralia
2026-09-24 · CISA Cybersecurity Advisories · score 7.25
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-5430 WSO2 Multiple Products Path Traversal Vulnerability CVE-2026-71362 Adobe Commerce and Magento Incorrect Authorization Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. While BOD 26-04 applies only to FCEB…
NORTHCOMVulns & exploitsPolicy & guidanceBreach & leaked dataUnited States
2026-09-24 · SecurityWeek · score 7.5
Three vulnerabilities in Salesforce Agentforce allowed hackers to hijack trusted agents, steal data, and launch phishing attacks.
SPACECOMCloud & identityVulns & exploitsSocial engineering
2026-09-24 · CERT/CC Vulnerability Notes (Carnegie Mellon SEI) · score 7.75
Overview ViewSonic vCast software, which is included in ViewBoard smartboard devices, contains multiple vulnerabilities that an attacker can chained to achieve full device compromise. Description ViewSonic ViewBoards are widely used smart display devices (smartboard), typically deoloyed in enterprise and educational environments. vCast is ViewSonic’s proprietary software suite for wireless connection between smartboards, which are Android-based systems, and devices running a client application. Three distinct vulnerabilities, all invoking unauthenticated endpoints, have been identified within the vCast suite. CVE-2026-82989 vCast’s media streaming service allows a remote attacker to exfiltrate JPEG images of screen content via GET requests to an unauthenticated /snapshot or /screen API endpoint. CVE-2026-82988 vCast’s Android Package Kit (APK) delivery mechanism allows a remote attacker to trigger unprivileged file installation by providing a malicious APK URL through an unauthenticated download endpoint. CVE-2026-82987 vCast’s network services allow a remote attacker to inject arbitrary input into service endpoints via HTTP requests to exposed unauthenticated endpoints Impact An…
NORTHCOMVulns & exploitsSupply chainApps & devices
2026-09-24 · CERT/CC Vulnerability Notes (Carnegie Mellon SEI) · score 8
Overview Door access controllers used on Norwegian Cruise Line (NCL) ships contain an improper authentication vulnerability that permits a replayed unique identifer (UID) from a radio-frequency identification (RFID) device to grant unauthorized entry to areas secured by these controllers. Description Norwegian Cruise Line is a global cruise company that operates a modern fleet sailing to destinations worldwide. As described in CVE-2026-75907 , the affected card reader authenticates NFC credentials only by checking their static 7-byte UID. A UID is not a secret and does not support cryptographic challenge‑response operations, so it cannot serve as a reliable authentication factor. Although the keycard's NTAG212 tag contains a memory block with a printed serial number and a value resembling a signature, the reader does not inspect this data during the access-control process. Validation based solely on UID constitutes identification rather than authentication. Because the credential performs no cryptographic exchange and offers no defense against cloning, any device capable of replaying or emulating UIDs can reproduce a functioning keycard. Impact An attacker with brief physical…
NORTHCOMVulns & exploitsPolicy & guidanceSupply chain
2026-09-24 · Inside GNSS · via Space Watch · score 8
The Space Force is turning a prototype effort to detect GPS jamming and spoofing using commercial satellites into a permanent, worldwide monitoring operation,...
SPACECOMNORTHCOMSpace & SATCOMvia Space Watch
2026-09-24 · CyberScoop · score 8.5
New federal programs take years to launch and fund. State and local governments need cybersecurity software now. The One Big Beautiful Bill already enables tax incentives. Congress should clarify and deploy them.
NORTHCOMCENTCOMCritical infrastructureBreach & leaked dataICS / OTUnited StatesRussia
2026-09-24 · CyberScoop · score 8.75
The Justice Department said two leaders of the company have been arrested and face conspiracy to commit wire fraud.
NORTHCOMEUCOMAPT & espionageScams & fraudUnited StatesRussia
2026-09-24 · CyberScoop · score 9
A new Democratic bill in Congress would establish a federal Cybersecurity and AI Board of Investigations to provide independent government oversight of cyberattacks carried out by AI agents, following recent hacks by models run at companies like Anthropic, OpenAI, Meta and others. The bill, introduced by Sen. Ed Markey, D-Mass., would attempt to establish a […]
NORTHCOMPACOMAI & cyberBreach & leaked dataSupply chainUnited StatesAustralia
2026-09-24 · Microsoft Security / MSTIC · score 9
Storm-2570 is a ransomware affiliate that uses consistent post-compromise tools and techniques across deployments involving Qilin, DragonForce, Anubis, and BERT ransomware, and provides guidance to help defenders detect and disrupt this activity before ransomware deployment.
EUCOMNORTHCOMRansomwarePolicy & guidanceCloud & identityQilinUnited StatesUK
2026-09-24 · CISA Cybersecurity Advisories · score 9.5
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to run system level commands or execute arbitrary code. The following versions of Eufy Omni C20, Omni X10 Pro are affected: Omni C20 <1.6.4 (CVE-2026-93289, CVE-2026-93290, CVE-2026-93291) Omni X10 Pro <1.6.4 (CVE-2026-93289) CVSS Vendor Equipment Vulnerabilities v3 9.4 Eufy Eufy Omni C20, Omni X10 Pro Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Use of Hard-coded Credentials, Improper Certificate Validation Background Critical Infrastructure Sectors: Information Technology Countries/Areas Deployed: Worldwide Company Headquarters Location: China Vulnerabilities Expand All + CVE-2026-93289 The affected products are vulnerable to command injection attack that could allow an unauthenticated attacker to execute system commands during the pairing process. View CVE Details Affected Products Eufy Omni C20, Omni X10 Pro Vendor: Eufy Product Version: Eufy Omni C20: <1.6.4, Eufy Omni X10 Pro: <1.6.4 Product Status: known_affected Remediations Mitigation Eufy recommends users to upgrade to version 1.6.4 or later. Relevant CWE: CWE-78 Improper…
PACOMNORTHCOMVulns & exploitsCritical infrastructureSupply chainChina
2026-09-24 · CISA Known Exploited Vulnerabilities · score 10.25
Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability. Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec request. This vulnerability can be chained to achieve unauthenticated exploitation of CVE-2026-86060. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Due 2026-09-28.
NORTHCOMVulns & exploitsPolicy & guidanceBreach & leaked dataUnited StatesKEV
2026-09-24 · CISA Known Exploited Vulnerabilities · score 10.25
Microsoft SharePoint Code Injection Vulnerability. Microsoft SharePoint contains a code injection vulnerability which could allow an authorized attacker to execute code over a network. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Due 2026-09-28.
NORTHCOMVulns & exploitsCloud & identityPolicy & guidanceUnited StatesKEV
2026-09-24 · CISA Known Exploited Vulnerabilities · score 10.25
WordPress Core Remote File Inclusion Vulnerability. WordPress Core contains a remote file inclusion vulnerability which could allow an unauthenticated attacker to make page-template resolution include a chosen readable local `.php` file outside the active theme directories, leading to remote code execution. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Due 2026-09-28.
NORTHCOMVulns & exploitsPolicy & guidanceBreach & leaked dataUnited StatesKEV
2026-09-24 · The Register — security · score 11
Operator’s AI bill averaged just $25 per completed scan
NORTHCOMPACOMSupply chainVulns & exploitsAI & cyberChina
2026-09-24 · The Record (Recorded Future) · score 13.75
U.S. Sens. Mark Warner (D-VA) and Ted Cruz (R-TX) introduced the Telecommunications Cybersecurity and Resilience Act on Thursday, arguing that the new effort was necessary in light of the Salt Typhoon attacks which saw Chinese hackers breach nearly all of the major telecommunications giants in the U.S.
PACOMNORTHCOMTelecom & cablesAPT & espionageBreach & leaked dataSalt TyphoonChinaUnited States
2026-09-24 · CyberScoop · score 15
The legislation from Senate Intelligence Vice-Chairman. Mark Warner, D-Va., and Senate Commerce Chairman Ted Cruz, R-Tex., would create a government-industry group to write voluntary best practices.
NORTHCOMPACOMTelecom & cablesAPT & espionagePolicy & guidanceSalt TyphoonChinaUnited States
2026-09-24 · Nextgov/FCW — cybersecurity · score 15
The bipartisan bill would establish cybersecurity best practices and independent certification, following the FCC’s rollback of safeguards adopted in response to the Chinese hacking campaign.
NORTHCOMPACOMTelecom & cablesAPT & espionagePolicy & guidanceSalt TyphoonChinaUnited States
2026-09-23 · The Hacker News · score 2.5
Cybersecurity researchers have disclosed details of an active TeamFiltration campaign codenamed UNK_CondorFiltration that has targeted over 5,700 accounts across 28 Microsoft 365 tenants. According to Proofpoint, the activity has primarily focused on Chilean retail and financial institutions. It originated from 1,487 unique AWS EC2 source IP addresses. "The campaign compromised 7 accounts –
NORTHCOMCloud & identity
2026-09-23 · SecurityWeek · score 2.5
Karen Vardanyan has also been ordered to pay over $1.2 million in restitution to victims.
NORTHCOMRansomware
2026-09-23 · The Hacker News · score 2.75
A use-after-free in the Linux kernel's AF_UNIX socket subsystem can be used to escape a container and gain root on the host, security firm DepthFirst said in research published September 22. The flaw, tracked as CVE-2026-80521 (CVSS score: 7.8), was fixed upstream on August 6, but Ubuntu has not shipped the patch for its 26.04, 24.04, or 22.04 LTS releases. DepthFirst
NORTHCOMVulns & exploits
2026-09-23 · Canadian Centre for Cyber Security · score 3
Vulns & exploits
2026-09-23 · The Hacker News · score 3
A Windows malware called CLOSEDQUORUM is built to take orders from a vote of up to four AI models instead of an attacker's server, Cisco Talos said on September 22. The models can choose to steal Windows credentials, saved browser passwords, and crypto wallet data. Talos has not seen this setup work from start to finish, and the public version of the malware does not work as it is.
Malware & toolingAI & cyber
2026-09-23 · Rapid7 blog · score 3
Security teams already have long queues of potential application vulnerabilities. The useful question is what happens next: can they see how a weakness behaves in a running application, reproduce the attack, and give developers enough evidence to fix it? Dynamic application security testing (DAST) helps answer those questions by testing applications as an attacker encounters them. The IDC MarketScape: Worldwide Dynamic Application Security Testing 2026 Vendor Assessment (Doc #US54119126, September 2026). The IDC MarketScape evaluated 16 vendors and named Rapid7 a Leader. We believe the result reflects the strength of Rapid7’s DAST capabilities, but the IDC MarketScape also offers a useful view of where the category is heading. DAST has developed beyond traditional web scanning into a source of runtime evidence that can help organizations validate risk across the application layer. From possible weakness to validated application risk Code analysis and dependency scanning help teams identify weaknesses before an application is deployed. DAST provides a different view by interacting with the assembled application while it is running. It can show what happens when a particular…
Supply chainVulns & exploits
2026-09-23 · Canadian Centre for Cyber Security · score 3
Vulns & exploits
2026-09-23 · Canadian Centre for Cyber Security · score 3
Vulns & exploits
2026-09-23 · Canadian Centre for Cyber Security · score 3
Vulns & exploits
2026-09-23 · Canadian Centre for Cyber Security · score 3
Vulns & exploits
2026-09-23 · The Hacker News · score 3
The private email address GitLab gives you for filing issues by email is a credential. Anyone who gets it can email a patch that GitLab commits in your name, to any branch you can push to, including main, and can start CI/CD jobs that run as you. GitLab shows each user this address behind a button labeled "Email work item to this project." Mail sent to it opens an issue in that project, authored
Breach & leaked dataVulns & exploits
2026-09-23 · Canadian Centre for Cyber Security · score 3.25
Vulns & exploits
2026-09-23 · BleepingComputer · score 3.5
Attackers are increasingly targeting the management systems used to control enterprise infrastructure, with several critical vulnerabilities actively exploited before or shortly after vendors disclosed them. [...]
NORTHCOMVulns & exploitsSupply chain
2026-09-23 · CIS / MS-ISAC advisories · score 3.75
Multiple vulnerabilities have been discovered in Adobe products, the most severe of which could allow for arbitrary code execution. Adobe Bridge is a creative asset manager that lets you preview, organize, edit, and publish multiple creative assets quickly and easily. Adobe Connect is a secure, highly customizable web conferencing and virtual training platform used for webinars, online meetings, and e-learning. Adobe InDesign is a professional page layout and desktop publishing software used for designing and publishing content for both print and digital media. Adobe Premiere Pro is a subscription-based timeline video editing software for film, TV, and web. Adobe Substance 3D is a suite of tools for creating 3D content, including modeling, texturing, and rendering. Adobe Experience Manager (AEM) is a comprehensive content management solution for building websites, mobile apps, and forms. Content Authenticity SDK contains Rust and JavaScript libraries, enabling web pages to read, validate, create, and sign manifest data, and embed it in supported asset files. Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution in the context…
NORTHCOMVulns & exploits
2026-09-23 · The Hacker News · score 3.75
Two MikroTik RouterOS SSH vulnerabilities chained together let attackers take full administrative control of Internet-exposed routers without a password, SSH key, or completed authentication. The chain, which CERT Polska calls MikroTrick, combines an SSH state-machine flaw (CVE-2026-67279) with an argument-injection bug in the RouterOS login process (CVE-2026-86060). Attack logs date to at
Apps & devicesVulns & exploits
2026-09-23 · Canadian Centre for Cyber Security · score 4
Vulns & exploitsSupply chain
2026-09-23 · Canadian Centre for Cyber Security · score 4
Vulns & exploitsSupply chain
2026-09-23 · Canadian Centre for Cyber Security · score 4
Vulns & exploitsCloud & identity
2026-09-23 · CyberScoop · score 4.5
The white paper is the latest step in trying to create a “Quality Era” for the Common Vulnerabilities and Exposures (CVE) program as the number of CVEs surges.
NORTHCOMVulns & exploitsBreach & leaked dataUnited States
2026-09-23 · The Hacker News · score 4.75
Unknown threat actors have managed to compromise two legitimate MemTensor packages across the npm and Python Package Index (PyPI) repositories to push a platform-specific Go-based implant dubbed sckit designed for Windows, Linux, and macOS. According to reports from Aikido, SafeDep, Socket, and StepSecurity, the libraries in question below - @memtensor/memos-cloud-openclaw-plugin versions
Supply chainMalware & toolingPolicy & guidance
2026-09-23 · Canadian Centre for Cyber Security · score 4.75
Vulns & exploitsApps & devices
2026-09-23 · Recorded Future — Insikt · score 4.75
Explore Insikt Group's analysis on Russia's escalation of hybrid and New Generation Warfare (NGW) tactics across Europe since 2022, including cyber attacks, physical sabotage, and airspace incursions, along with projected trends for the next two years.
EUCOMCritical infrastructureRussiaUkraine
2026-09-23 · CERT/CC Vulnerability Notes (Carnegie Mellon SEI) · score 5
Overview Cinnamon's Kotaemon (all versions up to v0.12.0) multi‑user chat interface does not verify conversation ownership when loading a conversation. Any authenticated user can read, delete, rename, or overwrite another user’s conversation data by supplying the correct ID. This results in high‑impact confidentiality, integrity, and availability violations. Description Cinnamon's Kotaemon is an open‑source, retrieval‑augmented generation (RAG) based tool that lets you build a chatbot capable of "chatting with your documents". As discussed in CVE-2026-86867 , all versions up to v0.12.0 fail to verify conversation ownership when loading a conversation. In multi‑user mode, each conversation row includes a user field that identifies its owner. The four affected handlers, select_conv, delete_conv, rename_conv, and persist_chat_suggestions , query conversations using select(Conversation).where(Conversation.id == conversation_id) No predicate is included to ensure Conversation.user == user_id . As a result, any authenticated user can operate on conversations they do not own. Impacted operations include: * select_conv – reads the full chat transcript, RAG retrieval history (verbatim…
NORTHCOMVulns & exploits
2026-09-23 · BleepingComputer · score 5.5
OpenAI agents targeted public data providers in multiple countries, probing some for vulnerabilities and exploiting a security weakness in an Australian government portal while performing information-retrieval tasks as part of a research project. [...]
PACOMVulns & exploitsAustralia
2026-09-23 · The Record (Recorded Future) · score 6
An Armenian national and member of the Ryuk ransomware gang was sentenced to two years in federal prison for his role in launching attacks.
NORTHCOMSPACECOMRansomwareUnited States
2026-09-23 · The Register — security · score 6
Customers got crime crew's calling card instead of access to journals
Breach & leaked dataSupply chainAI & cyberScattered SpiderShinyHunters
2026-09-23 · CERT/CC Vulnerability Notes (Carnegie Mellon SEI) · score 6
Overview Imprivata Enterprise Access Management (EAM), an authentication and single sign-on platform for enterprise and clinical environments, contains a vulnerability in versions 26.2.6 and below. The product provides no supported mechanism to rotate its RSA key pair after deployment, meaning the same key pair is used indefinitely to generate the appliance's X.509 certificate. Description CVE-2026-82356 Imprivata EAM uses an RSA key pair to generate the X.509 certificate that identifies the appliance to the clinical workstations, Electronic Health Record (EHR) platforms, and shared-device workflows that rely on it for authentication. After reviewing the product documentation and engaging Imprivata support, it was confirmed that no supported mechanism exists to rotate this RSA key pair after deployment. Using a single RSA key pair indefinitely for certificate generation violates cryptographic best practices. Because the key cannot be rotated, an attacker who obtains the private key retains a valid, trusted appliance identity for as long as the deployment remains in service, with no supported means to revoke or replace it short of redeploying the product. Impact An attacker who…
NORTHCOMCloud & identityVulns & exploitsSocial engineering
2026-09-23 · Canadian Centre for Cyber Security · score 6
Vulns & exploitsApps & devicesCloud & identity
2026-09-23 · CyberScoop · score 6.5
An AI compact built around capability, control, and continuity can ensure the country stays safe and secure while also leading the world in the technology.
NORTHCOMAI & cyberCritical infrastructureTelecom & cablesUnited States
2026-09-23 · The Hacker News · score 6.75
ClickFix has become the most common way attackers get into enterprise networks, and it does it without an exploit, an attachment, or a file on disk. Our new global threat report traces the technique from a novelty in late 2023 to a subscription product with on-chain infrastructure and a state-sponsored user base, and explains why blocking malicious domains is no longer a useful defense. Read
Malware & toolingSocial engineeringAPT & espionage
2026-09-23 · CyberScoop · score 7.5
A Ukrainian official said the government will use the tools to automate cybersecurity functions in critical infrastructure as the war with Russia continues.
EUCOMNORTHCOMCritical infrastructureAI & cyberVulns & exploitsUkraineRussia
2026-09-23 · CISA Cybersecurity Advisories · score 7.5
Introduction The Federal Bureau of Investigation (FBI) and Cybersecurity and Infrastructure Security Agency (CISA)—hereafter referred to as the “authoring agencies”—have published this fact sheet to highlight considerations for critical infrastructure entities to reduce risk and minimize vulnerabilities when working with third-party industrial control system (ICS) integrators. ICS is an umbrella term referring to integrated networks of hardware and software designed to monitor and automate physical processes, encompassing specialized control systems and devices, such as supervisory control and data acquisition (SCADA) systems and programmable logic controllers. Third-party integrators provide varying types of services for ICS, such as control system design, installation, operational data analysis, device support and service, and daily operational control. Critical infrastructure owners and operators should maintain caution when granting third-party ICS integrators high levels of access or control over industrial processes, ensuring the principle of least privilege (PoLP), is applied. PoLP within OT environments lends itself to granting users, processes, and systems only the…
NORTHCOMICS / OTCritical infrastructureSupply chainUnited States
2026-09-23 · CyberScoop · score 7.5
The Armenian national was extradited from Ukraine to the United States last year and pleaded guilty to cybercrimes in July.
NORTHCOMEUCOMRansomwareCritical infrastructureBreach & leaked dataUnited StatesUkraine
2026-09-23 · Via Satellite · via Space Watch · score 8.5
Viasat has received a $42 million task order under its contract to provide managed satcom services to the U.S. Marine Corps. Viasat has a background in providing managed satcom to […]
NORTHCOMSPACECOMSpace & SATCOMUnited Statesvia Space Watch
2026-09-23 · The Register — security · score 9
Used generic unattended email to reveal incident, which may have spread to multiple agencies
PACOMNORTHCOMAI & cyberPolicy & guidanceAustralia
2026-09-23 · CISA Known Exploited Vulnerabilities · score 10.25
WSO2 Multiple Products Path Traversal Vulnerability . WSO2 API Control Plane, API Manager, Traffic Manager & Universal Gateway contain a path traversal vulnerability that could allow for unrestricted file upload and lead to remote code execution. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Due 2026-09-27.
NORTHCOMVulns & exploitsPolicy & guidanceBreach & leaked dataUnited StatesKEV
2026-09-23 · CISA Known Exploited Vulnerabilities · score 10.25
Adobe Commerce and Magento Incorrect Authorization Vulnerability . Adobe Commerce and Magento contains an incorrect authorization vulnerability that could allow an attacker to leverage this vulnerability to gain elevated access to sensitive resources without any user interaction. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Due 2026-09-27.
NORTHCOMVulns & exploitsPolicy & guidanceBreach & leaked dataUnited StatesKEV
2026-09-23 · The Register — security · score 12
Good news: there's a patch. Bad news: both CISA and F5 warn that it's under active exploitation
NORTHCOMPACOMVulns & exploitsSupply chainCloud & identityUNC5221 / UNC5174United StatesChina
2026-09-22 · The Hacker News · score 2.5
A new flaw in the Linux kernel's KVM virtualization code for ARM64 processors can leave a freed piece of host memory exposed to a guest virtual machine on hosts with nested virtualization enabled. The bug, tracked as CVE-2026-89775, allows a guest to read and write host kernel memory, and the researcher who found it says it can be used to escape the guest and run code on the host machine.
NORTHCOMVulns & exploits
2026-09-22 · SecurityWeek · score 2.5
Posing as the legitimate sorted-btree package, indexed-btree hides a malware trigger in its prototype method.
Supply chainMalware & tooling
2026-09-22 · Canadian Centre for Cyber Security · score 3
Vulns & exploits
2026-09-22 · Canadian Centre for Cyber Security · score 3
Vulns & exploits
2026-09-22 · BleepingComputer · score 3
An Armenian man was sentenced to 24 months in prison and 3 years of supervised release for hacking U.S. companies and encrypting their systems in Ryuk ransomware attacks. [...]
NORTHCOMRansomwareUnited States
2026-09-22 · The Hacker News · score 3
Attackers are exploiting a critical flaw in F5 BIG-IP Access Policy Manager (APM) that lets them run code on a BIG-IP system without logging in, F5 says. The flaw, CVE-2026-94127, affects only systems in which APM serves as an OAuth authorization server, issuing access tokens to applications. F5 disclosed it in an advisory on September 22 and has released engineering hotfixes.
Vulns & exploitsCloud & identity
2026-09-22 · Rapid7 blog · score 3.5
Overview On September 22, 2026, F5 published a security advisory for CVE-2026-94127 , a critical heap-based buffer overflow vulnerability affecting F5 BIG-IP Access Policy Manager (APM). The vulnerability has a CVSS v3.1 score of 9.8. An unauthenticated attacker with network access to an affected virtual server may be able to achieve remote code execution (RCE) by sending specifically crafted traffic. BIG-IP APM provides identity-aware access control for applications and other corporate resources and can integrate with authentication technologies including OAuth, OpenID Connect, and SAML. CVE-2026-94127 is not exposed in a default configuration: exploitation requires a BIG-IP virtual server with both an APM access policy and an OAuth profile configured. Because affected BIG-IP systems may process traffic at an organization's network edge, organizations using this configuration should prioritize remediation. The vulnerability affects the data plane and does not expose the BIG-IP control plane. BIG-IP systems operating in Appliance mode are also affected. F5 lists the following affected release trains and corresponding fixed hotfixes: BIG-IP 21.1.0: versions prior to…
NORTHCOMVulns & exploitsCloud & identity
2026-09-22 · Canadian Centre for Cyber Security · score 4
Vulns & exploitsSupply chain
2026-09-22 · BleepingComputer · score 4
D-Link warned customers of a maximum-severity vulnerability (CVE-2026-86296) with public proof-of-concept (PoC) exploit code and no patch, affecting legacy DIR-822A dual-band Wi-Fi routers. [...]
Vulns & exploitsApps & devices
2026-09-22 · The Hacker News · score 4
A zero-day proof-of-concept tool that stops Microsoft Defender from installing platform and signature updates by filling all available disk space was published on GitHub on September 19. The tool, called BigDiskBuster, has no patch, no CVE, and no Microsoft advisory. Its author, Abdelhamid Naceri, is a former Microsoft security researcher whose earlier Defender exploits were used in
NORTHCOMVulns & exploits
2026-09-22 · BleepingComputer · score 5
A new Windows malware named ClosedQuorum uses Google Gemini, DeepSeek, Qwen, and Mistral AI models to autonomously determine the actions to take during post-compromise stages of an attack. [...]
NORTHCOMMalware & toolingApps & devicesAI & cyber
2026-09-22 · CIS / MS-ISAC advisories · score 5
A vulnerability has been discovered in F5 BIG-IP Access Policy Manager (APM) that could allow for remote code execution. BIG-IP APM is a widely deployed network access and identity management solution used across government agencies, financial institutions, healthcare organizations, and large enterprises to control application and network access. Successful exploitation of this vulnerability could result in an attacker gaining full control of the affected system. Depending on the privileges associated with the account, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Accounts configured to have fewer user rights on the system could be less impacted than those that operate with administrative user rights.
NORTHCOMVulns & exploitsCloud & identity
2026-09-22 · CISA Cybersecurity Advisories · score 5.25
View CSAF Summary Multiple Siemens products are vulnerable to the "Copy Fail" vulnerability. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available. The following versions of Siemens SIPLUS and SIMATIC Products are affected: SIMATIC AX Runtime Core Linux Common Debian vers:all/* (CVE-2026-31431) SIMATIC AX Runtime Core Linux Common Debian arm64 vers:all/* (CVE-2026-31431) SIMATIC AX Runtime Core Linux Platform Container Common Debian Development vers:all/* (CVE-2026-31431) SIMATIC AX Runtime Core Linux VMWare Development vers:all/* (CVE-2026-31431) SIMATIC CN 4100 vers:intdot/<6.0 (CVE-2026-31431) SIMATIC HMI MTP1000 Unified Basic (6AV2123-3KB32-0AW0) vers:intdot/<21.0.2.1 (CVE-2026-31431) SIMATIC HMI MTP1000 Unified Comfort Panel (6AV2128-3KB06-0AX1) vers:intdot/<21.0.2.1 (CVE-2026-31431) SIMATIC HMI MTP1000 Unified Comfort Panel hygienic (6AV2128-3KB40-0AX0) vers:intdot/<21.0.2.1 (CVE-2026-31431) SIMATIC HMI MTP1000 Unified Comfort Panel hygienic neutral design (6AV2128-3KB70-0AX0)…
ICS / OTVulns & exploits
2026-09-22 · The Hacker News · score 5.25
The cyber extortion group known as ShinyHunters on Tuesday claimed it had breached the U.S. Federal Bureau of Investigation and stolen data belonging to current and former employees at the agency. "We have compromised the FBI. We hold very sensitive data on almost ALL FBI Agents and individuals who filed an application with the FBI for a job," the group said in a statement posted on their dark
NORTHCOMBreach & leaked dataRansomwareShinyHuntersUnited States
2026-09-22 · SecurityWeek · score 5.5
A Chinese threat actor has exploited the bug to exfiltrate sensitive information from nearly 1,000 ZyXEL switches.
PACOMVulns & exploitsChina
2026-09-22 · DefenseScoop · score 5.5
Gen. Randall Reed called AI an “engineered vulnerability” in the hands of foes who may use it to manipulate algorithms and lead military logisticians into making “catastrophic decisions based on hallucinated intelligence.”
NORTHCOMSupply chainVulns & exploitsUnited States
2026-09-22 · BleepingComputer · score 5.5
A Chinese-speaking threat actor has been exploiting vulnerabilities in ZyXEL GS1900 Smart Managed Switches and WordPress to steal sensitive data from 996 devices and more than 18,500 records stored in backend databases. [...]
PACOMVulns & exploitsChina
2026-09-22 · SANS Internet Storm Center · score 5.5
Introduction
NORTHCOMSocial engineeringRansomwareMalware & tooling
2026-09-22 · CERT/CC Vulnerability Notes (Carnegie Mellon SEI) · score 6
Overview Vendor-signed UEFI Shell applications may allow an attacker to bypass Secure Boot protections by abusing commands such as mm (Memory Modify). On systems that trust the affected vendor’s certificate or include the application’s Authenticode hash in the UEFI Authorized Signature Database (DB), an attacker with sufficient access could use the application’s direct memory-access capabilities to disable or circumvent Secure Boot enforcement and execute untrusted UEFI code. To mitigate this risk, system administrators should apply available firmware and software updates from affected hardware vendors. Description The Unified Extensible Firmware Interface ( UEFI ) standard defines the firmware architecture used to initialize hardware and transfer control to modern operating systems during system startup. On systems with Secure Boot enabled, UEFI applications and drivers must be cryptographically signed and verified before their execution. Trust for these signatures is managed through several databases, including the Authorized Signature Database (DB), which commonly contains certificates from original equipment manufacturer (OEM) vendors, operating system authorities, and other…
NORTHCOMSPACECOMSupply chain
2026-09-22 · The Hacker News · score 6.25
A SharePoint Server vulnerability that Microsoft initially classified as a spoofing flaw with a CVSS score of 6.5 actually enables authenticated remote code execution, according to full technical details published today by Viettel Cyber Security researcher Dinh Ho Anh Khoa. The flaw, CVE-2026-65660, affects SharePoint Server 2016, 2019, and Subscription Edition. Patches have been
Vulns & exploitsSpace & SATCOMCloud & identity
2026-09-22 · CyberScoop · score 6.5
SpyCloud’s study found 1,787 of the approximately 10,000 U.S. organizations had it, including one infected device that saved logins for 167 utility metering tenants.
CENTCOMNORTHCOMCritical infrastructureMalware & toolingBreach & leaked dataIranUnited States
2026-09-22 · DefenseScoop · score 6.5
DOD leaders discussed MSS at the 2026 DefenseTalks conference, hosted by DefenseScoop.
NORTHCOMCENTCOMAI & cyberAPT & espionagePolicy & guidanceUnited StatesChina
2026-09-22 · Recorded Future — Insikt · score 6.5
Recorded Future's Insikt GroupⓇ has been tracking ClickFix, a social engineering technique that turns a familiar logo or verification prompt into the entry point for an attack. Here's what that research reveals about catching it, and why it's now running inside Malicious Site Monitoring, part of our newly launched Digital Risk Protection solution.
NORTHCOMSPACECOMSocial engineeringMalware & tooling
2026-09-22 · CISA Cybersecurity Advisories · score 6.75
View CSAF Summary Industrial Edge Management contains an authentication bypass vulnerability that could allow an unauthenticated remote attacker to perform full account takeover by resetting user credentials without completing email verification. Siemens has released new versions for the affected products and recommends to update to the latest versions. The following versions of Siemens Industrial Edge Management are affected: Industrial Edge Management Cloud vers:all/* (CVE-2026-18963) Industrial Edge Management Pro V1 vers:intdot/>=1.14.9|<1.15.20 (CVE-2026-18963) Industrial Edge Management Pro V2 vers:intdot/>=2.2.0|<2.2.2 (CVE-2026-18963) Industrial Edge Management Virtual vers:intdot/>=2.6.0|<2.9.1 (CVE-2026-18963) CVSS Vendor Equipment Vulnerabilities v3 9.1 Siemens Siemens Industrial Edge Management Weak Password Recovery Mechanism for Forgotten Password Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-18963 A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access…
EUCOMVulns & exploitsICS / OTCloud & identity
2026-09-22 · BleepingComputer · score 6.75
The ShinyHunters extortion gang claims it breached FBI systems using a new Oracle PeopleSoft zero-day vulnerability, gaining access to internal services and stealing sensitive data on employees and job applicants. [...]
NORTHCOMVulns & exploitsBreach & leaked dataRansomwareShinyHuntersUnited States
2026-09-22 · Via Satellite · via Space Watch · score 6.75
CybExer, an Estonian cybersecurity company, is to play a key role in helping keep the EU’s future secure satellite connectivity system, IRIS² secure. It will lead a ten-company European consortium […]
EUCOMSPACECOMSpace & SATCOMvia Space Watch
2026-09-22 · CISA Cybersecurity Advisories · score 7
View CSAF Summary A Client Code Execution (CCE) vulnerability has been identified in Desigo CC, potentially allowing malicious actors to execute arbitrary code on client devices through specially crafted graphics documents. This vulnerability leverages user-defined graphics containing embedded scripts that are executed on client application instances. Successful exploitation could lead to compromise of the client operating system and potential lateral movement within the organization. The following versions of Siemens Desigo CC family are affected: Desigo CC family V6 vers:all/* (CVE-2026-34223) Desigo CC family V7 vers:all/* (CVE-2026-34223) CVSS Vendor Equipment Vulnerabilities v3 8.2 Siemens Siemens Desigo CC family Improper Control of Generation of Code ('Code Injection') Background Critical Infrastructure Sectors: Critical Manufacturing, Commercial Facilities Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-34223 The affected application is vulnerable to Client Code Execution (CCE) due to insufficient input validation when handling scripts embedded within user-defined graphics documents. Specifically, when the…
EUCOMVulns & exploitsICS / OTCritical infrastructure
2026-09-22 · CISA Cybersecurity Advisories · score 7
View CSAF Summary SIMOVE Fleetmanager and SIPLANT contain a path traversal vulnerability that could allow an attacker to access files outside of intended scope. Siemens has released new versions for the affected products and recommends to update to the latest versions. The following versions of Siemens SIMOVE Fleetmanager and SIPLANT are affected: SIMOVE Fleetmanager V3.1 vers:intdot/<3.1.13 (CVE-2026-67367) SIMOVE Fleetmanager V3.2 vers:intdot/<3.2.4 (CVE-2026-67367) SIMOVE Fleetmanager V3.3 vers:intdot/<3.3.2 (CVE-2026-67367) SIMOVE Fleetmanager V4.0 vers:intdot/<4.0.1 (CVE-2026-67367) SIPLANT V1.7 vers:all/* (CVE-2026-67367) SIPLANT V2.2 vers:all/* (CVE-2026-67367) SIPLANT V3.0 vers:all/* (CVE-2026-67367) SIPLANT V3.1 vers:intdot/<3.1.4 (CVE-2026-67367) CVSS Vendor Equipment Vulnerabilities v3 8.6 Siemens Siemens SIMOVE Fleetmanager and SIPLANT Relative Path Traversal Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-67367 Affected devices do not properly validate and neutralize directory traversal sequences in the file-serving endpoint of the…
EUCOMVulns & exploitsICS / OTCritical infrastructure
2026-09-22 · The Register — security · score 7
This time it's personal
NORTHCOMVulns & exploitsRansomwareBreach & leaked dataShinyHuntersUnited States
2026-09-22 · CISA Cybersecurity Advisories · score 7.25
View CSAF Summary The products listed below contain a denial of service vulnerability that could allow an attacker to force the devices into protection mode under certain conditions. This disables remote connectivity functions (Web Access) to the devices. Siemens has released new versions for the affected products and recommends to update to the latest versions. The following versions of Siemens WTV676 and WTV776 are affected: WTV676-HB6035 Web Interface vers:intdot/<3.94 (CVE-2026-89207) WTV776-HB6035 Web Interface vers:intdot/<4.17 (CVE-2026-89207) CVSS Vendor Equipment Vulnerabilities v3 6.5 Siemens Siemens WTV676 and WTV776 Improper Validation of Specified Type of Input Background Critical Infrastructure Sectors: Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-89207 Affected devices do not properly validate input received from backend services. This could allow an unauthenticated remote attacker to force the device into protection mode, which results in losing remote connectivity functions (Web Access). View CVE Details Affected Products Siemens WTV676 and WTV776 Vendor: Siemens Product Version:…
EUCOMVulns & exploitsICS / OTCritical infrastructure
2026-09-22 · Cisco Talos · score 7.25
CLOSEDQUORUM, a malware binary discovered through Cisco Talos’ CAIRN project, exhibits fully autonomous command and control (C2). It represents a shift in effort displacement for attackers, in which expanding portions of the attack chain can be executed without operator involvement.
NORTHCOMCYBERCOMMalware & toolingAI & cyberSocial engineering
2026-09-22 · Cisco Talos · score 7.25
Talos is releasing CAIRN, a research toolkit for hunting, classifying, and tracking emerging AI-integrated malware.
SPACECOMMalware & toolingAI & cyberApps & devices
2026-09-22 · CISA Cybersecurity Advisories · score 7.25
CISA added Check Point VPN, Arista VeloCloud and F5 APM flaws to KEV; F5 confirmed zero-day use.
VPNs and access proxies are the front door to partner networks.
Recommend reviewing S6 patch status.
NORTHCOMVulns & exploitsUnited StatesAI-curated
2026-09-22 · Canadian Centre for Cyber Security · score 7.25
NORTHCOMVulns & exploitsPolicy & guidanceSupply chainCanada
2026-09-22 · CISA Cybersecurity Advisories · score 7.5
View CSAF Summary A vulnerability has been identified in the Open Interface Services (OIS) web module affecting Siveillance Control and Siveillance Control Pro (versions OIS 3.x.y and OIS 4.x.y) . This vulnerability allows an attacker to upload arbitrary files, which can lead to unauthorized root-level access on the OIS server. Siemens has released patches and updates for Siveillance OIS to apply to the products that incorporate the OIS service, and recommends to update to the latest versions. The following versions of Siemens Siveillance Control are affected: Siveillance Control Pro V3.0 vers:intdot/<3.0.12.2173 (CVE-2026-50093) Siveillance Control Pro V4.0 vers:intdot/<4.0.9.2178 (CVE-2026-50093) Siveillance Control V3.0 vers:intdot/<3.0.22.2177 (CVE-2026-50093) Siveillance Control V4.0 vers:intdot/<4.0.11.2177 (CVE-2026-50093) CVSS Vendor Equipment Vulnerabilities v3 9 Siemens Siemens Siveillance Control Unrestricted Upload of File with Dangerous Type Background Critical Infrastructure Sectors: Critical Manufacturing, Communications, Commercial Facilities Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-50093 A…
EUCOMVulns & exploitsICS / OTPolicy & guidance
2026-09-22 · CyberScoop · score 7.5
The FBI jobs site, which was temporarily defaced, remains unavailable and the agency said it’s investigating the claims.
NORTHCOMRansomwareCloud & identityBreach & leaked dataShinyHuntersScattered SpiderUnited States
2026-09-22 · CISA Cybersecurity Advisories · score 7.75
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to hijack session cookies and issue state-changing requests as an operator which would allow the attacker to control the programmable logic controller and the physical processes it drives. The following versions of OpenPLC Runtime v3 are affected: OpenPLC 3 (CVE-2026-88020) CVSS Vendor Equipment Vulnerabilities v3 6.1 Autonomy Logic OpenPLC Runtime v3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Background Critical Infrastructure Sectors: Critical Manufacturing, Energy, Transportation Systems, Water and Wastewater Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-88020 The affected product is susceptible to an improper neutralization of input during web page generation vulnerability when the web interface attempts to route the program based on a query string parameter with no encoding. View CVE Details Affected Products OpenPLC Runtime v3 Vendor: Autonomy Logic Product Version: Autonomy Logic OpenPLC: 3 Product Status: known_affected Remediations Vendor fix Autonomy Logic…
NORTHCOMVulns & exploitsCritical infrastructureICS / OTUnited States
2026-09-22 · The Hacker News · score 7.75
A Chinese threat actor codenamed UTA0565 has been observed exploiting the recently disclosed Google Chrome-Microsoft Windows exploit chain as zero-days through fake websites. The attacks, detected on September 3 and 4, 2026, involved the chaining of two vulnerabilities in Chrome (CVE-2026-85046, CVE-2026-87491) and one impacting Windows Advanced Local Procedure Call (CVE-2026-85880) to break
PACOMVulns & exploitsMalware & toolingUTA0565China
2026-09-22 · CISA Cybersecurity Advisories · score 8
View CSAF Summary Successful exploitation of this vulnerability could result in a system crash, a DoS, or memory corruption, which could lead to code execution on the victim system. The following versions of lwIP (Lightweight IP) are affected: API >=2.0.1|<=2.2.1 (CVE-2026-91018) CVSS Vendor Equipment Vulnerabilities v3 8.8 lwIP lwIP (Lightweight IP) Double Free Background Critical Infrastructure Sectors: Chemical, Communications, Critical Manufacturing, Energy, Financial Services, Healthcare and Public Health, Transportation Systems, Water and Wastewater Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: Sweden Vulnerabilities Expand All + CVE-2026-91018 The affected product has a double free vulnerability, which could crash the system, cause a DoS, memory corruption, or allow code execution on the victim system. View CVE Details Affected Products lwIP (Lightweight IP) Vendor: lwIP Product Version: lwIP API: >=2.0.1|<=2.2.1 Product Status: known_affected Remediations Mitigation Users of lwIP are encouraged to update their version of lwIP using the repository found at https://cgit.git.savannah.gnu.org/cgit/lwip.git . The commit identifier that contains the…
EUCOMNORTHCOMVulns & exploitsCritical infrastructureICS / OT
2026-09-22 · CISA Cybersecurity Advisories · score 8
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to gain full code execution on the device. The following versions of lwIP TCP/IP Stack MQTT Client Application are affected: MQTT Client Application >=2.0.1|<=2.2.1 (CVE-2026-87121) CVSS Vendor Equipment Vulnerabilities v3 9.8 lwIP lwIP TCP/IP Stack MQTT Client Application Out-of-bounds Write Background Critical Infrastructure Sectors: Chemical, Communications, Critical Manufacturing, Energy, Financial Services, Healthcare and Public Health, Transportation Systems, Water and Wastewater Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: Sweden Vulnerabilities Expand All + CVE-2026-87121 The affected product is vulnerable to an out-of-bounds write, which may allow an attacker to gain full code execution on the device. View CVE Details Affected Products lwIP TCP/IP Stack MQTT Client Application Vendor: lwIP Product Version: lwIP MQTT Client Application: >=2.0.1|<=2.2.1 Product Status: known_affected Remediations Mitigation Users of lwIP are encouraged to update their version of lwIP using the repository found at https://savannah.nongnu.org/projects/lwip . The commit…
EUCOMNORTHCOMVulns & exploitsCritical infrastructureICS / OT
2026-09-22 · DefenseScoop · score 8.5
Technology leaders warn that legacy monitoring tools create critical blind spots across complex cloud architectures and are no longer sustainable to support autonomous and AI-dependent systems.
NORTHCOMVulns & exploitsSpace & SATCOMSupply chainUnited States
2026-09-22 · Breaking Defense · via TJFSCC Daily · score 9.25
Australia’s LAND 4140 program aims to modernize the Australian military’s land-based C4I architecture across all domains
SPACECOMPACOMSpace & SATCOMAustraliavia TJFSCC Daily
2026-09-22 · Via Satellite · via Space Watch · score 9.75
Boeing Defence Australia selected New York-based Lite Coms to provide tactical satellite terminals for a beyond-line of sight (BLOS) satcom program for the Australian Defence Force (ADF). Under the award […]
PACOMSPACECOMSpace & SATCOMAustraliavia Space Watch
2026-09-22 · The Register — security · score 12
China’s AI darling goes on the defense after engineer highlighted Grok-esque security flaws
PACOMNORTHCOMSupply chainVulns & exploitsAI & cyberScattered SpiderChina
2026-09-22 · CyberScoop · score 13
The threat group Volexity tracks as UTA0565 showcased a variance in tactics, but it used the same exploit kit as multiple Chinese threat groups.
PACOMNORTHCOMVulns & exploitsAPT & espionageSocial engineeringUTA0565Linen / Violet TyphoonChinaUnited States
2026-09-21 · The Hacker News · score 2.75
The North Korean threat actors behind the Contagious Interview campaign have compromised at least 30,000 devices located in more than 100 countries and siphoned funds or account credentials from over 7,000 cryptocurrency wallets, according to a new joint cybersecurity advisory. The primary targets of the campaign are individual web designers, engineers, and specialists in cryptocurrency,
PACOMWaterPlumNorth Korea
2026-09-21 · Canadian Centre for Cyber Security · score 3
Vulns & exploits
2026-09-21 · SecurityWeek · score 3
It’s unclear if the attacks are part of previous campaigns against Rust, but the techniques used by the attackers match those used by North Korea.
PACOMNORTHCOMNorth KoreaROK
2026-09-21 · Canadian Centre for Cyber Security · score 3
Vulns & exploits
2026-09-21 · Canadian Centre for Cyber Security · score 3
Vulns & exploits
2026-09-21 · The Hacker News · score 3
Malware already running on a Mac can quietly take over Meta's Muse assistant and use the broad access its owner granted the app, security researcher Patrick Wardle has shown in a proof-of-concept released on September 21. It works by changing a hidden setting so that when the user taps the microphone and dictates a prompt, the words go to the attacker instead of Meta. The flaw is in
Malware & toolingVulns & exploits
2026-09-21 · The Hacker News · score 3
A new flaw in WordPress core let an anonymous visitor leave a comment that planted a hidden script on the page. If a logged-in administrator later opened that page, the script could run code on the site's server. WordPress fixed the flaw, tracked as CVE-2026-93485 and called "Comment2Shell," on September 17 in version 7.1.1 and told site owners to update right away. There is
Vulns & exploitsHacktivism & DDoS
2026-09-21 · BleepingComputer · score 3.25
​Attackers are now actively exploiting a high-severity vulnerability in Zyxel GS1900 series switches, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). [...]
NORTHCOMVulns & exploitsUnited States
2026-09-21 · The Hacker News · score 3.25
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a now-patched security flaw impacting Zyxel GS1900 series switches to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026-7273 (CVSS score: 8.8), is a stack-based buffer overflow vulnerability that could result in arbitrary operating
NORTHCOMVulns & exploitsUnited States
2026-09-21 · Canadian Centre for Cyber Security · score 4
Vulns & exploitsBreach & leaked data
2026-09-21 · DefenseScoop · score 4
The fielding comes after two Army divisions experimented with NGC2 for more than a year and nearly two months after the service tested the architecture at a capstone event in the Mojave Desert, leading senior service officials to start pushing the prototype to additional units.
NORTHCOMSPACECOMSpace & SATCOMCloud & identity
2026-09-21 · SANS Internet Storm Center · score 4.25
Microsoft Security Research published an interesting blog post " TerminalFix campaign deploys a reverse tunnel through multistage intrusion " about a malware campaign. The aspect that I want to take a closer look at, is the fact that the threat actors used PNG files with steganography. I reached out to the researchers and they kindly shared the IOCs for the PNG files with me.
NORTHCOMApps & devicesMalware & tooling
2026-09-21 · Canadian Centre for Cyber Security · score 4.25
Vulns & exploitsSupply chain
2026-09-21 · BleepingComputer · score 4.25
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning that hackers are exploiting three Linux kernel vulnerabilities, one of them rated critical. [...]
NORTHCOMVulns & exploitsMalware & toolingUnited States
2026-09-21 · The Hacker News · score 5
A browser. A plugin. A package. A login screen. Normal stuff. That is basically the problem this week. The trouble keeps showing up inside things people already trust: code that takes a bad turn, old payloads coming back, exposed systems, weak checks, fake fixes, and attack paths that look almost too easy. Even the research side is getting messy, with more findings, more automation, and not
Vulns & exploitsSocial engineeringAI & cyber
2026-09-21 · Infosecurity Magazine · score 5
ShinyHunters has claimed responsibility for hacking the Clop ransomware group, defacing its leak site and alleging theft of key operational data
RansomwareBreach & leaked dataCl0pShinyHunters
2026-09-21 · The Record (Recorded Future) · score 5.25
The ShinyHunters extortion group hijacked the dark web leak site of the prolific Cl0p ransomware gang, according to material posted on the site over the weekend.
RansomwareBreach & leaked dataCl0pShinyHunters
2026-09-21 · Canadian Centre for Cyber Security · score 5.25
NORTHCOMVulns & exploitsStandards & complianceUnited States
2026-09-21 · Canadian Centre for Cyber Security · score 5.25
Vulns & exploitsSupply chain
2026-09-21 · DefenseScoop · score 5.5
The contract awards will support the GHOST-R initiative.
SPACECOMNORTHCOMSpace & SATCOMSupply chainUnited States
2026-09-21 · GAO reports · score 6
What GAO Found The Federal Aviation Administration (FAA) has identified electromagnetic spectrum-related threats, including spoofing and jamming, to the National Airspace System (NAS) and international flight routes. However, FAA has not completed risk and mitigation assessments, and updated security documentation needed to address these threats. Additionally, FAA did not have a defined, real-time monitoring and detection capability for all spectrum-related threats. Without comprehensive risk and mitigation assessments, complete security documentation, and real-time monitoring capabilities, FAA may not have sufficient information to identify, prioritize, and respond to evolving spectrum-related threats. As a result, spoofing, jamming, and other attacks could disrupt aviation communications, degrade situational awareness, and increase the risk of operational disruptions. Potential Cyberattacks Impacting Aircraft Communications FAA participates in multiple collaborative efforts with other federal agencies as well as non-federal aviation industry stakeholders regarding cybersecurity. FAA's collaborative efforts fully addressed two of the eight leading practices and partially…
NORTHCOMSpace & SATCOMUnited States
2026-09-21 · Via Satellite · via Space Watch · score 6.5
Intellian Technologies and Network Innovations plan to jointly develop and distribute multi-band Wideband Global Satcom (WGS) flyaway terminals for military and government customers under a new strategic partnership announced last […]
SPACECOMSpace & SATCOMvia Space Watch
2026-09-21 · The Register — security · score 7
Rival crew demands eight figures and threatens to expose companies that paid to keep quiet
RansomwareVulns & exploitsBreach & leaked dataCl0pShinyHunters
2026-09-21 · The Register — security · score 7
Ad biz promises users control while bug could expose voice prompts
SPACECOMAI & cyberVulns & exploitsMalware & tooling
2026-09-21 · CISA Cybersecurity Advisories · score 7.25
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-7273 Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based…
NORTHCOMVulns & exploitsPolicy & guidanceBreach & leaked dataUnited States
2026-09-21 · Check Point Research · score 8.5
For the latest discoveries in cyber research for the week of 21st Setpember, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Japan’s Digital Agency, which operates the Government Solution Service used by multiple ministries, has confirmed a data breach after attackers exploited a vulnerability in a VPN appliance. Approximately 246,000 records were exposed, […]
NORTHCOMPACOMVulns & exploitsAI & cyberMalware & toolingJapanUnited States
2026-09-21 · CISA Known Exploited Vulnerabilities · score 10.25
Arista VeloCloud Orchestrator Improper Input Validation Vulnerability. Arista VeloCloud Orchestrator (VCO) on-prem contains an improper input validation vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Due 2026-09-25.
NORTHCOMVulns & exploitsPolicy & guidanceBreach & leaked dataUnited StatesKEV
2026-09-21 · CISA Known Exploited Vulnerabilities · score 10.25
Check Point Multiple Products Path Traversal Vulnerability. Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent contain a path traversal vulnerability that allows an unauthenticated attacker to upload and execute arbitrary scripts. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Due 2026-09-25.
NORTHCOMVulns & exploitsPolicy & guidanceBreach & leaked dataUnited StatesKEV
2026-09-21 · CISA Known Exploited Vulnerabilities · score 10.25
Check Point Multiple Products Improper Certificate Validation Vulnerability. Check Point Security Gateway and Check Point Spark Firewall using Site to Site VPN or Remote Access VPN contain an improper certificate validation vulnerability which could allow an unauthenticated remote attacker to execute arbitrary code on the Gateway. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Due 2026-09-25.
NORTHCOMVulns & exploitsPolicy & guidanceBreach & leaked dataUnited StatesKEV
2026-09-21 · SecurityWeek · score 11.5
The US, Japan, Germany and Australia have published a joint report detailing the scope of North Korea’s WaterPlum campaign.
PACOMNORTHCOMDPRK & crypto theftDPRK IT workersWaterPlumNorth KoreaJapan
2026-09-21 · Volexity · score 13.5
On September 9, 2026, Volexity published a blog post detailing the simultaneous use of multiple chained zero-day exploits in Google Chrome (CVE-2026-85046, CVE-2026-87491) and Microsoft Windows (CVE-2026-85880) by two different […]
NORTHCOMPACOMVulns & exploitsAPT & espionageSocial engineeringUTA0565ChinaUnited States
2026-09-20 · SecurityWeek · score 3
Attackers could exploit the flaws to cause denial-of-service conditions, disclose memory, or modify memory.
Vulns & exploitsHacktivism & DDoS
2026-09-20 · BleepingComputer · score 3.75
An ongoing npm malware campaign involving the 'indexed-btree' package shows how threat actors bypass supply chain defenses by hiding malicious code in a package's normal runtime behavior rather than in installation scripts. [...]
Supply chainMalware & tooling
2026-09-20 · The Hacker News · score 3.75
Threat actors are leveraging ClickFix-like lures to deliver a previously undocumented remote access trojan (RAT) called ChainScript. "ChainScript has appeared under multiple build names, including ComponentTask33, UpdateDigital, HostShared, and OrchidViolet66, while presenting itself as Spotify, Zoom Workplace, and Microsoft Teams software," Blackpoint Adversary Pursuit Group (APG)
NORTHCOMSocial engineeringMalware & tooling
2026-09-20 · South China Morning Post (China) · via TJFSCC Daily · score 7
Scientists in China have simulated a drone attack on one of the country’s major suspension bridges to determine the vulnerability of key transport hubs to modern warfare tactics. The researchers found that a drone carrying just 30kg (66lbs) of TNT could trigger a bridge collapse if it detonated within inches of the main suspension cable at the point where it meets a support tower. The targeted bridge strikes that have featured in Russia’s war on Ukraine show that warfare has shifted from mass...
PACOMEUCOMVulns & exploitsChinaRussiavia TJFSCC Daily
2026-09-20 · The Hacker News · score 10.25
The North Korean threat actor known as Jade Sleet has been attributed to the compromise of an India-based "much smaller organization" in the information technology (IT) services industry, once again highlighting how the adversary continues to target developers to breach target networks. Cybersecurity company SentinelOne, which disclosed details of the activity, said it involved the use of Apple
PACOMAPT & espionageMalware & toolingBreach & leaked dataWaterPlumNorth KoreaIndia
2026-09-20 · CISA Known Exploited Vulnerabilities · score 10.25
Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability. Zyxel GS1900 series switches contain a stack-based buffer overflow vulnerability in the CGI program which could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Due 2026-09-24.
NORTHCOMVulns & exploitsPolicy & guidanceBreach & leaked dataUnited StatesKEV
2026-09-19 · BleepingComputer · score 3.75
A joint law enforcement advisory warns that the North Korean hacking group WaterPlum compromised at least 30,000 devices worldwide from December 2025 through July 2026 and transferred more than $10.7 million in stolen cryptocurrency to North Korea. [...]
PACOMWaterPlumNorth KoreaROK
2026-09-19 · BleepingComputer · score 5
The ShinyHunters extortion gang breached the Clop (aka Cl0p) ransomware operation's data leak site, defacing the Tor site and allegedly stealing server data and the private keys for its onion service. [...]
RansomwareBreach & leaked dataCl0pShinyHunters
2026-09-18 · Canadian Centre for Cyber Security · score 3
Vulns & exploits
2026-09-18 · Canadian Centre for Cyber Security · score 3
Vulns & exploits
2026-09-18 · Canadian Centre for Cyber Security · score 3
Vulns & exploits
2026-09-18 · Canadian Centre for Cyber Security · score 3
Vulns & exploits
2026-09-18 · Canadian Centre for Cyber Security · score 3
Vulns & exploits
2026-09-18 · BleepingComputer · score 3
The Gyazo image-sharing platform has confirmed it suffered a data breach after hackers exploited a server vulnerability that allowed them to steal 23.6 million user records. [...]
Breach & leaked dataVulns & exploits
2026-09-18 · Canadian Centre for Cyber Security · score 3.25
Vulns & exploits
2026-09-18 · The Hacker News · score 3.25
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added three security flaws impacting the Linux kernel to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilities are listed below - CVE-2025-39682 (CVSS score: 9.8) - An improper check for unusual or exceptional conditions vulnerability in the TLS receive path
NORTHCOMVulns & exploitsUnited States
2026-09-18 · SecurityWeek · score 3.25
Microsoft fixed vulnerabilities across Azure and AI-branded products, with privilege escalation flaws accounting for the majority.
Vulns & exploitsCloud & identity
2026-09-18 · Dark Reading · score 3.25
The authentication bypass flaw CVE-2026-76460 impacts Cisco's Identity Services Engine (ISE) and received a maximum 10 out of 10 CVSS score.
Vulns & exploitsCloud & identity
2026-09-18 · The Hacker News · score 3.5
A flaw in four widely used AI coding agents lets someone who controls a plugin's code repository swap the plugin an agent installs for a malicious one, even when the agent locked that plugin to a specific reviewed version, security firm Air Security said on Thursday. The firm said Anthropic has patched the flaw in Claude Code 2.1.179 and OpenAI in Codex 0.146.0, that GitHub Copilot has no
NORTHCOMAI & cyberVulns & exploits
2026-09-18 · SecurityWeek · score 3.75
Noteworthy stories that might have slipped under the radar: Mandiant's 2026 AI risk report, PhantomRaven malware used by bug bounty hunter, WordPress plugin bug exploited.
NORTHCOMRansomwareMalware & tooling
2026-09-18 · Canadian Centre for Cyber Security · score 4
Vulns & exploitsSupply chain
2026-09-18 · The Hacker News · score 4
SolarWinds has released security updates to address a high-severity flaw in Access Rights Manager (ARM) that, if successfully exploited, could lead to an unauthenticated remote code execution vulnerability. The vulnerability, tracked as CVE-2026-28326, is rated 8.8 out of 10.0 on the CVSS scoring system. The issue affects all versions of Access Rights Manager 2026.2 and prior. "SolarWinds
Vulns & exploitsSupply chainMalware & tooling
2026-09-18 · SecurityWeek · score 5
Gyazo maker Helpfeel said the attacker exploited a vulnerability in its image upload server to gain unauthorized access.
Breach & leaked dataVulns & exploitsPolicy & guidance
2026-09-18 · The Hacker News · score 5.25
Microsoft has released fixes for a maximum-severity security flaw in Azure AI Foundry that could be exploited to achieve privilege escalation. No customer action is required. The vulnerability, tracked as CVE-2026-85889, carries a CVSS score of 10.0. "Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network,"
Vulns & exploitsPolicy & guidanceCloud & identity
2026-09-18 · CyberScoop · score 6
The bug, since patched, gave attackers remote code execution privileges and access to user accounts and production environments, including Meta’s core product suite and an OpenAI software repository.
NORTHCOMVulns & exploitsSupply chainAI & cyber
2026-09-18 · Inside GNSS · via Space Watch · score 7
The growing dependence of telecommunications, energy, financial and computing infrastructure on GNSS timing is creating a corresponding security problem: the signals used to...
NORTHCOMSpace & SATCOMTelecom & cablesvia Space Watch
2026-09-18 · CISA Cybersecurity Advisories · score 7.25
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2025-39964 Linux Kernel Race Condition Vulnerability CVE-2026-53266 Linux Kernel Out-of-Bounds Write Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. While BOD 26-04 applies only to FCEB agencies, CISA encourages…
NORTHCOMVulns & exploitsPolicy & guidanceBreach & leaked dataUnited States
2026-09-18 · CISA Cybersecurity Advisories · score 7.25
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2025-39682 Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt…
NORTHCOMVulns & exploitsPolicy & guidanceBreach & leaked dataUnited States
2026-09-18 · The Hacker News · score 9
The Pakistan-aligned threat group tracked as Transparent Tribe (aka APT36 and Earth Karkaddan) has been attributed to a fresh set of cyber attacks targeting government and defense entities in India and Afghanistan. The attacks, per Zscaler ThreatLabz, involve the use of previously undocumented tools called RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH. The activity has been codenamed Operation
NORTHCOMCENTCOMMalware & toolingAPT & espionageIndia
2026-09-18 · The Japan Times · via TJFSCC Daily · score 9.25
The North Korean group, called WaterPlum, infected more than 30,000 devices with malware between December last year and July this year.
PACOMDPRK & crypto theftMalware & toolingWaterPlumNorth KoreaJapanvia TJFSCC Daily
2026-09-18 · The Hacker News · score 9.75
Cybersecurity researchers have discovered a cluster of 13 npm packages that have been found to deliver a previously undocumented JavaScript stealer codenamed WeaselBiscuit. The new malware family, per OpenSourceMalware, exhibits functional overlaps with two malware strains associated with the Democratic People's Republic of Korea's (DPRK) Contagious Interview campaign: BeaverTail and
PACOMMalware & toolingApps & devicesSupply chainWaterPlumROKNorth Korea
2026-09-18 · SentinelLabs · score 11.75
North Korean operators built a foothold on a DevOps engineer's Mac in a campaign whose job interview lures deliver malware via Terraform lock files.
NORTHCOMPACOMMalware & toolingDPRK & crypto theftSocial engineeringLazarus GroupWaterPlumNorth Korea
2026-09-18 · CyberScoop · score 14
A five-nation advisory attributed WaterPlum (Contagious Interview) to the DPRK 313 General Bureau.
30,000+ devices in 100+ countries and $10.71M from 7,000+ wallets; the lure also harvests credentials and IDs.
Consider warning technical staff and job-hunting families never to run interview code.
PACOMNORTHCOMAPT & espionageSocial engineeringcrypto_theftWaterPlumDPRK IT workersNorth KoreaJapanAI-curated
2026-09-17 · Canadian Centre for Cyber Security · score 3
Vulns & exploits
2026-09-17 · Canadian Centre for Cyber Security · score 3
Vulns & exploits
2026-09-17 · The Hacker News · score 3
Malicious code running inside a Docker Sandboxes virtual machine on macOS could escape the project directory shared into it and read or change files anywhere else on the host, Docker warns in a security announcement on September 15. The escape runs with the rights of the host account that runs the virtual machine. The flaw, CVE-2026-77179, is rated Critical, affects versions
Vulns & exploitsMalware & tooling
2026-09-17 · SecurityWeek · score 3.25
Hackers used a compromised API key to deploy a Cloudflare worker that injected malicious scripts.
NORTHCOMSupply chainMalware & tooling
2026-09-17 · Dark Reading · score 3.25
The move is consistent with the agency's advice on the need for organizations to prioritize the vulnerabilities that actually matter.
NORTHCOMVulns & exploitsUnited States
2026-09-17 · CIS / MS-ISAC advisories · score 3.25
Multiple vulnerabilities have been discovered in Oracle products, the most severe of which could allow for arbitrary code execution. Successful exploitation of the most severe of these vulnerabilities could result in an attacker gaining the same privileges as the logged-on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.
Vulns & exploits
2026-09-17 · CERT/CC Vulnerability Notes (Carnegie Mellon SEI) · score 4
Overview Dokploy versions 0.29.8 and 0.29.11, as well as commit 24b02f5 on the canary branch, are vulnerable to OS command injection during the backup creation and restoration processes. The vulnerability stems from unsanitized shell command construction that can allow an attacker to escalate privileges and lead to full compromise of the target device. Description Dokploy is an open-source Platform as a Service solution for deploying applications and databases on self-hosted servers. Dokploy allows authenticated users to create and schedule database backups and restore previously created backups. These backup operations are executed by the Dokploy process, which runs with root privileges by default. Dokploy is vulnerable to OS command injection in its database backup creation and restoration functionality due to insufficient sanitization of user-controlled input before it is incorporated into shell commands. The vulnerable backup functionality constructs database-specific shell commands that directly interpolate a user-supplied database name, while the restore functionality incorporates a user-supplied backupFile value into a shell command. Both operations ultimately pass the…
Vulns & exploitsSupply chain
2026-09-17 · CISA Cybersecurity Advisories · score 4.25
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker with access to the same network segment to tamper with communication data in the affected product by sending specially crafted packets under specific timing conditions. This could allow the attacker to cause a denial-of-service (DoS) condition in the affected product by interfering with its control function or causing it to operate incorrectly. The following versions of Mitsubishi Electric CC-Link IE TSN Communication Protocol (Update A) are affected: Mitsubishi Electric MELSEC MX Controller MX-R model MXR300-16 vers:all/* (CVE-2026-13584) Mitsubishi Electric MELSEC MX Controller MX-R model MXR300-32 vers:all/* (CVE-2026-13584) Mitsubishi Electric MELSEC MX Controller MX-R model MXR300-64 vers:all/* (CVE-2026-13584) Mitsubishi Electric MELSEC MX Controller MX-R model MXR500-128 vers:all/* (CVE-2026-13584) Mitsubishi Electric MELSEC MX Controller MX-R model MXR500-256 vers:all/* (CVE-2026-13584) Mitsubishi Electric MELSEC MX Controller MX-F model MXF100-8-N32 vers:all/* (CVE-2026-13584) Mitsubishi Electric MELSEC MX Controller MX-F model MXF100-8-P32 vers:all/* (CVE-2026-13584) Mitsubishi…
Vulns & exploitsHacktivism & DDoS
2026-09-17 · CISA Cybersecurity Advisories · score 4.25
View CSAF Summary Hitachi Energy is aware of vulnerabilities that affect the FACTS Control systems with GWS component listed in this document. An attacker exploiting these vulnerabilities can cause impact on confidentiality, integrity and availability of the product. Following FACTS Control systems with GWS component deployed from year 2020 onwards are likely affected by the above vulnerabilities. Product deployments without GWS component are not affected. • SVC Light (STATCOM) • Fixed Series Capacitor • Thyristor Controlled Series Capacitor • Static Var Compensator • Static Watt Compensator • Hybrid Synchronous Condensers Please refer to the Recommended Immediate Actions for information about the mitigation/remediation. The affected FCP versions are only applicable if GWS component is present. The following versions of Hitachi Energy FACTS Control Platform (FCP) are affected: FACTS Control Platform (FCP) 3.4.0, 3.7.0, 3.8.0, 3.10.0, 3.12.0, 3.14.0, 3.15.0, 4.0.0, 4.0.1, 4.1.0, 4.1.1 (CVE-2024-4872, CVE-2024-3980, CVE-2024-3982, CVE-2024-7940, CVE-2024-7941) CVSS Vendor Equipment Vulnerabilities v3 9.9 Hitachi Energy Hitachi Energy FACTS Control Platform (FCP) Improper…
Vulns & exploitsSupply chain
2026-09-17 · SANS Internet Storm Center · score 4.75
At the end of August, a malspam message was caught in the quarantine of a mail gateway operated by one of my customers. The message was not especially remarkable â;€;“; it asked the recipient to review some attached requirements and provide a price quotation for a fiber optic system and appeared to impersonate an employee of a legitimate company. ; ; The receiving gateway quarantined the message because it detected malicious content in the attachment, though even if it didnâ;€;™t, the e-mail would not have gotten much further due to failed SPF and DMARC checks. ;
NORTHCOMMalware & toolingSupply chainSocial engineering
2026-09-17 · War on the Rocks · via TJFSCC Daily · score 4.75
The war against Iran is putting new strains on U.S. military readiness by consuming munitions and missile defense interceptors, as well as through extended deployments, sustained operational demands, and the diversion of forces and attention from other theaters. Mark Cancian (Center for Strategic and International Studies), Stacie Pettyjohn (Center for a New American Security), and Michael Eisenstadt (Washington Institute for Near East Policy) join Ryan to unpack what readiness actually means, how the war is affecting it, what vulnerabilities have been exposed, and what it all means for deterrence and the U.S. military’s ability to respond to a crisis with
NORTHCOMCENTCOMVulns & exploitsUnited StatesIranvia TJFSCC Dailythink tank
2026-09-17 · Infosecurity Magazine · score 5
CISA released guidance on using cyber decoys to detect & disrupt malicious activity inside networks
NORTHCOMCritical infrastructurePolicy & guidanceUnited States
2026-09-17 · Canadian Centre for Cyber Security · score 5.25
Vulns & exploitsCloud & identityStandards & compliance
2026-09-17 · CyberScoop · score 5.5
The latest zero-day has a maximum-severity rating and affects Cisco Identity Services Engine, a product hit with three actively exploited vulnerabilities since June 2025.
Vulns & exploitsMalware & toolingPolicy & guidance
2026-09-17 · The Diplomat · via TJFSCC Daily · score 5.5
Beijing’s real vulnerability is not international action. It’s rising awareness within the Chinese population.
PACOMVulns & exploitsChinavia TJFSCC Daily
2026-09-17 · The Hacker News · score 6
Attackers keep finding new keys. The funny part is that defenders keep inventing where to store them. This week, those keys sit in AI tools, exposed services, old bugs, weak logins, and software sold like a monthly subscription. Some attacks use new tricks. Others just reuse what was already lying around. Both work often enough. So the threat landscape is not getting cleaner. It is just
Vulns & exploitsScams & fraudTelecom & cables
2026-09-17 · CISA Cybersecurity Advisories · score 6.75
View CSAF Summary ABB is aware of public reports of a vulnerability CVE‑2026‑31431 (Copy Fail) in the product versions listed as affected in the advisory. An update is available that resolves a publicly reported vulnerability. CVE‑2026‑31431 (Copy Fail) is a Linux kernel vulnerability that may allow a locally authenticated user or compromised container workload to gain elevated (root) privileges on affected systems. Once root access is obtained, the attacker can effectively gain complete control of the system The following versions of ABB Ability Edgenius are affected: Ability Edgenius >=3.2.0.0|<3.2.4.1, 3.2.4.1 (CVE-2026-31431) CVSS Vendor Equipment Vulnerabilities v3 7.8 ABB ABB Ability Edgenius Incorrect Resource Transfer Between Spheres Background Critical Infrastructure Sectors: Critical Manufacturing, Energy, Water and Wastewater, Chemical Countries/Areas Deployed: Worldwide Company Headquarters Location: Switzerland Vulnerabilities Expand All + CVE-2026-31431 A Linux kernel vulnerability that may allow a locally authenticated user or compromised container workload to gain elevated (root) privileges on affected systems. The issue originates in the Linux kernel’s…
Vulns & exploitsCritical infrastructureICS / OT
2026-09-17 · CISA Cybersecurity Advisories · score 6.75
View CSAF Summary Schneider Electric is aware of a vulnerability in its Modicon M340 https://www.se.com/ww/en/product-range/1468-modicon-m340-pac/ , BMXNOR0200H https://www.se.com/us/en/product/BMXNOR0200H/communication-module-modicon-m340-iec-608705101-104-dnp3-for-severe-environments/ : Modicon M340 X80 Ethernet Communication Modules, BMXNGD0100 https://www.se.com/us/en/product/BMXNGD0100/communication-module-modicon-m580-global-data-service/ : M580 Global Data module, BMXNOC0401 https://www.se.com/us/en/product/BMXNOC0401/network-module-modicon-m340-ethernet-ip-and-modbus-tcp-4-x-rj45/?pageType=product&sourceId=BMXNOC0401 : Modicon M340 X80 Ethernet Communication modules, BMXNOE0100 https://www.se.com/ww/en/product/BMXNOE0100/network-module-modicon-m340-modbus-tcp-1-x-rj45-flash-memory-card/?pageType=product&sourceId=BMXNOE0100 : Modbus/TCP Ethernet Modicon M340 module, BMXNOE0110 https://www.se.com/ww/en/product/BMXNOE0110/ethernet-tcp-ip-network-module-modicon-m340-automation-platform-flash-memory-card-internal-ram-16-mb-1-x-rj45-10-100/ : Modbus/TCP Ethernet Modicon M340 FactoryCast module product(s). Failure to apply the fix provided below may risk Denial Of Service…
NORTHCOMICS / OTVulns & exploitsHacktivism & DDoS
2026-09-17 · SpaceWatch.Global · via Space Watch · score 6.75
The European Union’s Galileo satellite navigation system has demonstrated its first civil authenticated position fix under real-world spoofing conditions, marking a step toward more resilient and trustworthy positioning for civilian users.
EUCOMSPACECOMSpace & SATCOMvia Space Watch
2026-09-17 · CISA Cybersecurity Advisories · score 7.25
View CSAF Summary Schneider Electric is aware of multiple vulnerabilities in its NetBotz 5 – 750/755 products.The NetBotz 5 – 750/755 products are security and environmental monitors providing temperature, humidity, leak, smoke, vibration, door contact, and video monitoring capabilities. Failure to apply the remediation provided below may risk arbitrary or remote code execution over the local network, which could result in device manipulation and unauthorized data access. The following versions of Schneider Electric NetBotz 5 750/755 are affected: NetBotz 5 750 vers:intdot/<=5.5.2 (CVE-2026-13336, CVE-2026-13337) NetBotz 5 755 vers:intdot/<=5.5.2 (CVE-2026-13336, CVE-2026-13337) CVSS Vendor Equipment Vulnerabilities v3 6.4 Schneider Electric Schneider Electric NetBotz 5 750/755 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), SQL Injection: Hibernate Background Critical Infrastructure Sectors: Commercial Facilities, Critical Manufacturing, Information Technology Countries/Areas Deployed: Worldwide Company Headquarters Location: France Vulnerabilities Expand All + CVE-2026-13336 CWE-78: Improper Neutralization of Special Elements used in…
EUCOMNORTHCOMVulns & exploitsICS / OTBreach & leaked data
2026-09-17 · Canadian Centre for Cyber Security · score 7.5
NORTHCOMVulns & exploitsCloud & identityStandards & complianceUnited States
2026-09-17 · Microsoft Security / MSTIC · score 7.5
AI has made fundamental changes to the operating environment for cybersecurity. Explore exposure management guidance on recommended controls and take action and stay ahead of cyberthreats.
NORTHCOMAI & cyberPolicy & guidanceVulns & exploitsAPT29Russia
2026-09-17 · CISA Cybersecurity Advisories · score 8
View CSAF Summary Schneider Electric is aware of vulnerabilities in its PowerChute Serial Shutdown product. The PowerChute Serial Shutdown product is a UPS management software enabling graceful system shutdown and energy management capabilities for desktops, servers and workstations. Failure to apply the remediation provided below may risk improper authentication validation which could result in disruption of operations and access to system data. The following versions of Schneider Electric PowerChute Serial Shutdown are affected: PowerChute Serial Shutdown vers:intdot/<=1.5, 1.6 (CVE-2026-13348) CVSS Vendor Equipment Vulnerabilities v3 5.3 Schneider Electric Schneider Electric PowerChute Serial Shutdown Improper Restriction of Excessive Authentication Attempts Background Critical Infrastructure Sectors: Commercial Facilities, Critical Manufacturing, Energy, Information Technology Countries/Areas Deployed: Worldwide Company Headquarters Location: France Vulnerabilities Expand All + CVE-2026-13348 CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow an attacker to gain unauthorized access to a user account by performing an…
EUCOMVulns & exploitsICS / OTPolicy & guidance
2026-09-17 · Canadian Centre for Cyber Security · score 8
NORTHCOMVulns & exploitsCloud & identityPolicy & guidanceUnited StatesCanada
2026-09-17 · CISA Cybersecurity Advisories · score 8.5
View CSAF Summary Successful exploitation of these vulnerabilities could allow unauthorized access to telemetry data and firmware. The following versions of Bransys ELD are affected: Android <11.00.00 (CVE-2026-86520, CVE-2026-86689, CVE-2026-77960) iOS <1.1.54 (CVE-2026-86520, CVE-2026-86689, CVE-2026-77960) CVSS Vendor Equipment Vulnerabilities v3 7.5 Bransys Bransys ELD Use of Hard-coded Credentials, Cleartext Transmission of Sensitive Information Background Critical Infrastructure Sectors: Transportation Systems Countries/Areas Deployed: United States Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-86520 The affected product is shipped with hardcoded MQTT credentials, which will grant read access to real-time data for every active device across a subset of carriers that were connected to the affected MQTT broker. View CVE Details Affected Products Bransys ELD Vendor: Bransys Product Version: Bransys Android: <11.00.00, Bransys iOS: <1.1.54 Product Status: known_affected Remediations Vendor fix Bransys recommends that users update their system through the app store. Android users should be on version 11.00.00 or newer. iOS users should be on…
NORTHCOMApps & devicesVulns & exploitsTelecom & cablesUnited States
2026-09-17 · The Record (Recorded Future) · score 8.75
Alleged Chinese hackers are breaking into government agencies across Latin America using a new backdoor that researchers are calling “SparroWocky.”
PACOMSOUTHCOMMalware & toolingSalt TyphoonChina
2026-09-17 · CISA Cybersecurity Advisories · score 9
View CSAF Summary Successful exploitation of this vulnerability could allow a local attacker to successfully authenticate even with an invalid block password by executing the affected product and modify part of the executable module in memory, and thereby allows the attacker to view, tamper with, destroy, or delete control programs. The following versions of Mitsubishi Electric GX Works3 and Motion Control Settings are affected: Mitsubishi Electric GX Works3 vers:all/* (CVE-2026-15688) Mitsubishi Electric Motion Control Settings (Software packaged with GX Works3) vers:all/* (CVE-2026-15688) CVSS Vendor Equipment Vulnerabilities v3 8.8 Mitsubishi Electric Mitsubishi Electric GX Works3 and Motion Control Settings Incorrect Implementation of Authentication Algorithm Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: Japan Vulnerabilities Expand All + CVE-2026-15688 Incorrect Implementation of Authentication Algorithm (CWE-303) vulnerability in the affected products allows a local attacker to successfully authenticate even with an invalid block password by executing the affected product and modify part…
PACOMVulns & exploitsCritical infrastructureSupply chainJapan
2026-09-17 · Focus Taiwan (CNA) · via TJFSCC Daily · score 9
Taipei, Sept. 18 (CNA) Premier Cho Jung-tai (卓榮泰) on Friday launched a new Taiwan-Matsu subsea cable, calling it part of the government's "preemptive preparations" to bolster communications resilience.
PACOMSPACECOMTelecom & cablesTaiwanvia TJFSCC Daily
2026-09-17 · CyberScoop · score 9.5
Cybercriminals used NightmareStresser to launch hundreds of thousands of DDoS attacks since at least 2022. Threat actors behind the operation claimed links to Russia.
NORTHCOMEUCOMHacktivism & DDoSRansomwareOPSEC & personal securityRussiaUnited States
2026-09-17 · Cisco Talos · score 10
Ransomware incidents in Japan rose 4.7% year over year. The Gentlemen was the most active group, with leak-site listings more than doubling from January to July. Qilin ranked second and appeared to use AI, while SMEs with capital under JPY 1 billion represented 80% of victims.
PACOMEUCOMRansomwareBreach & leaked dataQilinJapanPhilippines
2026-09-17 · Check Point Research · score 10
The defining development of the period came not from attackers but from the AI labs themselves, whose models broke out of controlled evaluations and reached real systems. In the wild, the criminal and state use of AI continued to mature along the lines tracked in earlier editions: models now act as attack operators, an underground […]
EUCOMNORTHCOMAI & cyberVulns & exploitsRansomwareUK
2026-09-17 · The Register — security · score 10
Eve's dropping in on Alice and Bob
PACOMNORTHCOMBreach & leaked dataVulns & exploitsAPT & espionageChina
2026-09-17 · CISA Known Exploited Vulnerabilities · score 10.25
Linux Kernel Race Condition Vulnerability. Linux Kernel contains a race condition vulnerability which allows concurrent writes to the same AF_ALG socket causing data to be unpredictably interleaved and creating inconsistencies in the socket's internal state. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Due 2026-09-21.
NORTHCOMVulns & exploitsPolicy & guidanceBreach & leaked dataUnited StatesKEV
2026-09-17 · CISA Known Exploited Vulnerabilities · score 10.25
Linux Kernel Out-of-Bounds Write Vulnerability. Linux Kernel contains an out-of-bounds write vulnerability in the ebtables SNAT target which allows an ARP sender hardware address rewrite to write directly into a nonlinear socket-buffer fragment backed by a splice-imported file page. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Due 2026-09-21.
NORTHCOMVulns & exploitsPolicy & guidanceBreach & leaked dataUnited StatesKEV
2026-09-17 · CISA Known Exploited Vulnerabilities · score 10.25
Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability. Linux Kernel contains an improper check for unusual or exceptional conditions vulnerability in the TLS receive path which allows a zero-length record retrieved from the rx_list to bypass the intended recvmsg() record-type handling, potentially causing subsequent TLS records to be processed using incorrect zero-copy and queuing assumptions. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Due 2026-09-21.
NORTHCOMVulns & exploitsPolicy & guidanceBreach & leaked dataUnited StatesKEV
2026-09-17 · The Hacker News · score 10.5
The China-aligned state-sponsored threat actor known as FamousSparrow has been observed deploying a previously unreported backdoor called SparroWocky in attacks targeting multiple countries in Latin America since at least August 2025. "SparroWocky is a modular, C++ backdoor," ESET security researchers Alexandre Côté Cyr and Romain Dumont said in a technical report shared with The Hacker News
PACOMSOUTHCOMMalware & toolingAPT & espionageSalt TyphoonChina
2026-09-17 · Dark Reading · score 11
Amid the US and China's fight for eco-colonial influence in Latin America, a stealthy backdoor has taken flight.
PACOMNORTHCOMAPT & espionageMalware & toolingSalt TyphoonChina
2026-09-17 · The Record (Recorded Future) · score 11.5
The FBI and Defense Department partnered with Japan’s National Police Agency and law enforcement agencies in Australia and Germany on a new advisory about “WaterPlum” — a group of cyber actors allegedly stealing cryptocurrency from job applicants by posing as AI or blockchain companies.
PACOMEUCOMDPRK & crypto theftWaterPlumNorth KoreaJapan
2026-09-17 · The Register — security · score 14.5
Beware the SparroWocky, my son! The backdoor that bites…
SOUTHCOMPACOMMalware & toolingAPT & espionageTelecom & cablesSalt TyphoonChinaUnited States
2026-09-16 · The Hacker News · score 2.5
The U.S. Department of Justice (DoJ) on Tuesday announced the court-authorized seizure of internet domains associated with a distributed denial-of-service (DDoS)-for-hire service known as NightmareStresser. The domains in question are: nightmare-stresser[.]com and nightmarestresser[.]org. Visitors to the sites are now greeted by a seizure banner that states - "This domain has been seized by
NORTHCOMHacktivism & DDoSUnited States
2026-09-16 · Canadian Centre for Cyber Security · score 3
Vulns & exploits
2026-09-16 · Canadian Centre for Cyber Security · score 3.25
Vulns & exploits
2026-09-16 · Canadian Centre for Cyber Security · score 3.25
Vulns & exploits
2026-09-16 · The Hacker News · score 3.25
Cisco has warned of a fresh maximum-severity security flaw impacting Identity Services Engine (ISE) that has come under active exploitation. The vulnerability, tracked as CVE-2026-76460 (CVSS score: 10.0), could allow an unauthenticated, remote attacker to bypass authentication. "This vulnerability is due to insufficient authentication control on an API endpoint," Cisco said. "An attacker
Vulns & exploitsCloud & identity
2026-09-16 · Canadian Centre for Cyber Security · score 4
Vulns & exploitsSupply chain
2026-09-16 · The Hacker News · score 4
A leaked credential shows up in a criminal marketplace, or a vulnerability gets a disclosure advisory, and either one can be weaponized against a real target before most security teams have triaged the alert. Attackers are combining that kind of intelligence with AI-assisted exploitation to accelerate the path from exposure to breach faster than most security programs are built to react.
Breach & leaked dataVulns & exploitsAI & cyber
2026-09-16 · The Hacker News · score 4.25
A critical security flaw in Issabel Framework, a web-based framework for the open-source unified communications PBX software, has come under active exploitation. The vulnerability in question is CVE-2026-89026 (CVSS v3.1 score: 9.8/CVSS v4.0 score: 9.3), which can allow an unauthenticated remote attacker to execute arbitrary operating system (OS) commands by taking advantage of a hard-coded
Standards & complianceVulns & exploitsSupply chain
2026-09-16 · Nextgov/FCW — cybersecurity · score 4.75
NIST is testing agentic AI to help enrich the National Vulnerability Database, even as increasingly capable models demonstrate why cyber autonomy needs careful containment.
NORTHCOMAI & cyberVulns & exploitsSupply chain
2026-09-16 · Canadian Centre for Cyber Security · score 5
Vulns & exploitsApps & devices
2026-09-16 · Breaking Defense · via TJFSCC Daily · score 5.75
The security protocol could offer a solution when a state faces a significant security threat that is not clearly armed aggression, including cyberattacks, the severing of undersea cables, or the protection of critical infrastructure.
EUCOMCritical infrastructureTelecom & cablesvia TJFSCC Daily
2026-09-16 · CISA News & Alerts · score 6
NORTHCOMPolicy & guidanceCritical infrastructureUnited States
2026-09-16 · Canadian Centre for Cyber Security · score 6
Vulns & exploitsCloud & identityCritical infrastructure
2026-09-16 · Cisco Talos · score 6
Advances in AI technology will continue to identify vulnerabilities that in some circumstances are difficult, or effectively impossible, to patch. Appropriate network segmentation, rigorous visibility, and the deployment of NGFW/IPS combinations can provide a powerful compensatory layer.
NORTHCOMVulns & exploitsAI & cyberMalware & tooling
2026-09-16 · South China Morning Post (China) · via TJFSCC Daily · score 6
The criminal trial of Huawei Technologies on racketeering charges shifted this week into a slower, more laborious pace in what is expected to be a weeks-long trial as the US Government sought to establish on Wednesday that Huawei was intent on learning about a proprietary robot developed by US telecommunications carrier T-Mobile. Matthew Skurnik, assistant US attorney for the Eastern District of New York, spent hours running FBI Special Agent James Diclemis through a series of emails that...
NORTHCOMTelecom & cablesChinaUnited Statesvia TJFSCC Daily
2026-09-16 · The Hacker News · score 6.5
Enterprises in Russia have emerged as the target of three threat activity clusters tracked as NightEagle, Hacking Cat, and Toy Ghouls, according to multiple reports from Kaspersky. The cybersecurity vendor said it has identified attacks mounted by NightEagle (aka APT-Q-95), a threat actor known to be active since at least 2023, that involve new techniques for persistence and lateral movement.
EUCOMMalware & toolingRansomwareAPT & espionageRussia
2026-09-16 · ESET WeLiveSecurity · score 6.5
ESET researchers document SparroWocky, the new flagship backdoor of the FamousSparrow APT group
Malware & toolingAPT & espionageSalt Typhoon
2026-09-16 · CERT/CC Vulnerability Notes (Carnegie Mellon SEI) · score 6.5
Overview A vulnerability in MLflow’s dspy and statsmodels model flavors allows unauthorized pickle deserialization executions despite a safety control. Specifically, the dspy flavor conditionally applies the control based on the model path’s file extension, and the statsmodels flavor does not apply the control. Description MLflow is an open-source platform for managing machine learning lifecycles, including model packaging, versioning, and deployment. "Flavors" refer to the specialized frameworks through which supported models are stored and loaded. In response to previous vulnerability concerns, MLflow implemented the MLFLOW_ALLOW_PICKLE_DESERIALIZATION safety control to block and disable executing any pickle deserialization and subsequent loads per the user’s choice. When loading models through mlflow.pyfunc.load_model(model) , users must specify a model flavor and path in an MLmodel file. With the dspy flavor, MLflow checks the value of MLFLOW_ALLOW_PICKLE_DESERIALIZATION , and whether the specified model path ends in .pkl . A model path that does not end in .pkl (even if the file is actually a pickle file), will route to a separate branch for pickle deserialization, bypassing…
NORTHCOMVulns & exploitsSupply chainPolicy & guidance
2026-09-16 · Canadian Centre for Cyber Security · score 7
NORTHCOMVulns & exploitsApps & devicesSupply chainUnited States
2026-09-16 · The Hacker News · score 7
Google has disclosed that a high-severity security flaw in its Pixel Cellular Modem has come under exploitation in the wild. The vulnerability, tracked as CVE-2026-58704 (CVSS score: 8.0), is a privilege escalation flaw. "In Cellular Modem, there is a possible permission bypass due to a logic error in the code," according to a description of the bug in the NIST National Vulnerability Database
Vulns & exploitsApps & devicesSpace & SATCOM
2026-09-16 · SANS Internet Storm Center · score 7
Earlier today, I noted an odd request showing up in our "First Seen" report:
NORTHCOMSPACECOMVulns & exploitsBreach & leaked dataUnited States
2026-09-16 · CISA Cybersecurity Advisories · score 7.5
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-76460 Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability CVE-2026-87886 Acronis Backup Incorrect Default Permissions Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. While BOD 26-04…
NORTHCOMVulns & exploitsPolicy & guidanceBreach & leaked dataUnited States
2026-09-16 · CISA Cybersecurity Advisories · score 7.5
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-58704 Google Pixel Improper Authorization Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management…
NORTHCOMVulns & exploitsPolicy & guidanceBreach & leaked dataUnited States
2026-09-16 · Recorded Future — Insikt · score 7.5
A behind-the-scenes look at how Recorded Future earned its spot as a threat intelligence leader in the latest Forrester Wave.
NORTHCOMVulns & exploitsAPT & espionageMalware & tooling
2026-09-16 · The Register — security · score 7.5
Agency's shift from static CVSS scores to risk-based prioritization sends the old format packing September 28
NORTHCOMVulns & exploitsPolicy & guidanceAI & cyberUnited States
2026-09-16 · CERT/CC Vulnerability Notes (Carnegie Mellon SEI) · score 8
Overview A vulnerability exists in Sentry Seer when the system is configured to automatically hand issues to a coding agent for remediation. Successful exploitation results in arbitrary code execution within the coding‑agent environment and access to connected source repositories. This vulnerability is tracked as CVE-2026-90999 . Description Sentry is a software error‑monitoring and performance‑tracking platform used by developers to detect, diagnose, and understand issues in their applications. It collects telemetry such as exceptions, stack traces, logs, and performance data from applications. Built into Sentry, Seer acts as an automated debugging assistant that converts telemetry into actionable remediation steps and can hand off issues to an integrated coding agent to propose code fixes. Because Sentry front-end projects commonly expose a public DSN (Data Source Name) to allow browsers to submit this telemetry, an attacker can craft and submit malicious events through this public endpoint. When Seer is enabled to automatically pass issues to a coding agent, these attacker-supplied events can traverse multiple trust boundaries. Ultimately, malicious event fields propagate…
NORTHCOMVulns & exploitsSpace & SATCOMSupply chain
2026-09-16 · Zscaler ThreatLabz · score 9
IntroductionIn August 2026, Zscaler ThreatLabz observed new activity by the Pakistan-nexus threat actor APT36 in a campaign we’re tracking as Operation RapidRust. Since our last publication about the group’s activity in January 2026, APT36 has maintained a high operational tempo and updated their tactics, techniques, and procedures (TTPs) in continued attacks targeting government and defense organizations in India and Afghanistan. During our investigation, ThreatLabz discovered new malware families and post-compromise tools, as well as significant post-compromise activity. The new tools include the RUSTYSHADE backdoor, the RUSTYMOVE post-compromise tool, and the PSNATCH and BASHNATCH file-stealing tools.In this blog post, we provide a detailed technical analysis of APT36’s new tooling and post-compromise activity. Key TakeawaysIn August 2026, ThreatLabz observed new activity by the Pakistan-nexus threat actor APT36 targeting government and defense entities in India and Afghanistan.RUSTYSHADE is a new Rust-based backdoor that abuses attacker-controlled private GitHub repositories for command-and-control (C2) and uses AES-256-GCM to encrypt C2 communications.RUSTYMOVE is a new…
CENTCOMPACOMAPT & espionageMalware & toolingIndia
2026-09-15 · Canadian Centre for Cyber Security · score 3
Vulns & exploits
2026-09-15 · Canadian Centre for Cyber Security · score 3
Vulns & exploits
2026-09-15 · Canadian Centre for Cyber Security · score 3
Vulns & exploits
2026-09-15 · Canadian Centre for Cyber Security · score 3
Vulns & exploits
2026-09-15 · The Hacker News · score 3
Threat actors are exploiting a critical security flaw in WooCommerce Wholesale Lead Capture, a premium WordPress plugin that has more than 6,000 active installs. "This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including PHP backdoors, and achieve remote code execution," Wordfence said. The WordPress security company said it has blocked over
Malware & toolingVulns & exploits
2026-09-15 · The Hacker News · score 3.25
With artificial intelligence (AI) shrinking the window between vulnerability discovery and exploitation and lowering the barrier to entry for bad actors, new findings from Sysdig show that skilled human operators can move just as swiftly after gaining initial access. In one instance highlighted by the cloud security company, the threat actor pivoted from a vulnerable Marimo notebook to an SSH
Vulns & exploitsCloud & identity
2026-09-15 · The Hacker News · score 3.75
A critical security flaw in WSO2 API Manager has come under active exploitation in the wild, according to findings from watchTowr. The vulnerability, tracked as CVE-2026-5430 (CVSS score: 9.8/10.0), is a case of improper verification of a cryptographic signature that could result in account takeover. Hacktron Team has been credited with discovering and reporting the flaw. "JWT authentication
Vulns & exploitsScams & fraud
2026-09-15 · CISA Cybersecurity Advisories · score 4
View CSAF Summary Successful exploitation of these vulnerabilities could grant full administrative control of the device, allowing an attacker to view live and recorded surveillance, alter device configurations, and use the device as a network pivot point. The following versions of Digital Watchdog VMAX DVR and NVR Product Lineups are affected: VMAX A1 G4 DVRs vers:all/* (CVE-2026-68953, CVE-2026-66890, CVE-2026-68070, CVE-2026-68950, CVE-2026-66887, CVE-2026-66372) VMAX IP G4 NVRs vers:all/* (CVE-2026-68953, CVE-2026-66890, CVE-2026-68070, CVE-2026-68950, CVE-2026-66887, CVE-2026-66372) VMAX A1 PLUS vers:all/* (CVE-2026-68953, CVE-2026-66890, CVE-2026-68070, CVE-2026-68950, CVE-2026-66887, CVE-2026-66372) VA1G4 Recorder vers:all/* (CVE-2026-68953, CVE-2026-66890, CVE-2026-68070, CVE-2026-68950, CVE-2026-66887, CVE-2026-66372) VG4 Recorder vers:all/* (CVE-2026-68953, CVE-2026-66890, CVE-2026-68070, CVE-2026-68950, CVE-2026-66887, CVE-2026-66372) CVSS Vendor Equipment Vulnerabilities v3 9.6 Digital Watchdog Digital Watchdog VMAX DVR and NVR Product Lineups Missing Authentication for Critical Function, Use of Hard-coded Credentials, Missing Authorization, Predictable Seed in…
Vulns & exploitsSupply chain
2026-09-15 · The Record (Recorded Future) · via TJFSCC Daily · score 4
Houston-based CenterPoint Energy notified federal regulators about an incident that exposed some customer data on the dark web.
NORTHCOMBreach & leaked dataCritical infrastructureUnited Statesvia TJFSCC Daily
2026-09-15 · CIS / MS-ISAC advisories · score 4.25
Multiple vulnerabilities have been discovered in Cisco Secure Email products, the most severe of which could allow for remote code execution. Cisco Secure Email Gateway (formerly ESA) is an email security appliance that filters spam, malware, and other threats at the mail gateway. Cisco Secure Email and Web Manager (formerly SMA) is a centralized management and reporting platform for Cisco Secure Email Gateway and Secure Web Appliance deployments. Successful exploitation of the most severe of these vulnerabilities could allow for remote code execution as root, which may lead to the complete compromise of the affected device.
Vulns & exploitsMalware & tooling
2026-09-15 · Inside GNSS · via Space Watch · score 5
Calian, a leader in high-precision GNSS antenna technology, today announced the expansion of its precision positioning and resilient PNT portfolio with three innovative...
SPACECOMSpace & SATCOMvia Space Watch
2026-09-15 · The Hacker News · score 5.5
Cybersecurity researchers have disclosed details of a multi-platform campaign that uses the Message Queueing Telemetry Transport (MQTT) protocol as a communication channel to control Windows and Linux systems. The emerging malware family, codenamed BambooToken, is assessed to be active since at least February 2023 and put to use in attacks targeting organizations across Asia and South America.
NORTHCOMSOUTHCOMMalware & toolingSpace & SATCOM
2026-09-15 · SANS Internet Storm Center · score 6.25
I have not done this type of diary in a while: What traffic will you see from a system on boot, before a user logs in? I just took a quick look at macOS 27 "Golden Gate" to see what traffic you should expect. Here are some of the highlights:
NORTHCOMApps & devicesSpace & SATCOM
2026-09-15 · The Register — security · score 6.5
The man allegedly wrote the code that powered the Lockergoga, MegaCortex, and Nefilim operations
EUCOMNORTHCOMRansomwareBreach & leaked dataMalware & toolingUkraineUnited States
2026-09-15 · Air & Space Forces Magazine · via TJFSCC Daily · score 6.5
Kearfott, a 108-year-old company, is seeing renewed demand for its inertial navigation and motion-control technologies as GPS jamming and spoofing increasingly threaten military operations. Kearfott’s Bob Carpenter explains how he supports aircraft, spacecraft, maritime systems, and missiles, while expanding production...
SPACECOMSpace & SATCOMvia TJFSCC Daily
2026-09-15 · CISA Cybersecurity Advisories · score 6.75
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to access privileged management functions or send arbitrary SMS messages through the connected GSM modem. The following versions of mySCADA myPRO Manager are affected: mySCADA myPRO Manager <=2.1 (CVE-2026-73807, CVE-2026-82567) CVSS Vendor Equipment Vulnerabilities v3 9.8 mySCADA Technologies mySCADA myPRO Manager Missing Authorization, Missing Authentication for Critical Function Background Critical Infrastructure Sectors: Critical Manufacturing, Energy, Food and Agriculture, Transportation Systems, Water and Wastewater Countries/Areas Deployed: Worldwide Company Headquarters Location: Czechia Vulnerabilities Expand All + CVE-2026-73807 The mySCADA myPRO Manager command API does not properly enforce authentication for privileged functions. An unauthenticated attacker with network access to the affected API could exploit this vulnerability to access privileged management functions. View CVE Details Affected Products mySCADA myPRO Manager Vendor: mySCADA Technologies Product Version: mySCADA Technologies mySCADA myPRO Manager: <=2.1 Product Status: known_affected Remediations Mitigation…
Vulns & exploitsCritical infrastructureICS / OT
2026-09-15 · CISA Cybersecurity Advisories · score 7
View CSAF Summary Mendix SAML module contains a vulnerability that could allow unauthenticated remote attackers to hijack an account in specific SSO configurations. Mendix has provided fix releases for the Mendix SAML module and recommends to update to the latest version. The following versions of Siemens Mendix SAML are affected: Mendix SAML (Mendix 10 compatible) vers:intdot/<4.2.3 (CVE-2026-80465) Mendix SAML (Mendix 11 compatible) vers:intdot/<4.2.3 (CVE-2026-80465) Mendix SAML (Mendix 9.24 compatible) vers:intdot/<3.6.27 (CVE-2026-80465) CVSS Vendor Equipment Vulnerabilities v3 8.7 Siemens Siemens Mendix SAML Improper Verification of Cryptographic Signature Background Critical Infrastructure Sectors: Critical Manufacturing, Information Technology Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-80465 Affected versions of the module do not properly validate the SAML response signature. This could allow unauthenticated remote attackers to hijack an account (session) in specific SSO configurations. View CVE Details Affected Products Siemens Mendix SAML Vendor: Siemens Product Version: Mendix SAML (Mendix 10…
EUCOMVulns & exploitsICS / OTCritical infrastructure
2026-09-15 · CISA Cybersecurity Advisories · score 7
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to deliver an unauthorized update, execute code, or extract credentials to allow the attacker to impersonate a privileged client. The following versions of Wärtsilä FOS-Onboard are affected: FOS-Onboard 5.07.0923.01 (CVE-2026-78225, CVE-2026-81855) CVSS Vendor Equipment Vulnerabilities v3 9.1 Wärtsilä Wärtsilä FOS-Onboard Use of Hard-coded Cryptographic Key Background Critical Infrastructure Sectors: Transportation Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: Finland Vulnerabilities Expand All + CVE-2026-78225 A hardcoded cryptographic server key vulnerability exists in the deployer-ng Update Controller component of Wärtsilä FOS-Onboard. View CVE Details Affected Products Wärtsilä FOS-Onboard Vendor: Wärtsilä Product Version: Wärtsilä FOS-Onboard: 5.07.0923.01 Product Status: known_affected Remediations Mitigation Wärtsilä states that the vulnerabilities are not exploitable when the product is installed as recommended, and has developed a security patch. Users are also directed to contact Wärtsilä to obtain and install the patch. To obtain and install the…
EUCOMVulns & exploitsSocial engineeringPolicy & guidance
2026-09-15 · CISA Cybersecurity Advisories · score 7
View CSAF Summary A reflected cross site scripting vulnerability in the authentication redirect flow (/auth/) of Teamcenter allows an unauthenticated remote attacker to inject JavaScript into an authenticated user's session by crafting a malicious URL. Successful exploitation may enable the attacker to read data or perform actions within the victim's Teamcenter session. Siemens has released new versions for the affected products and recommends to update to the latest versions. The following versions of Siemens Teamcenter are affected: Teamcenter V2412 vers:intdot/<2412.0013 (CVE-2026-58113) Teamcenter V2506 vers:intdot/<2506.0010 (CVE-2026-58113) Teamcenter V2512 vers:intdot/<2512.2607 (CVE-2026-58113) Teamcenter V2606 vers:intdot/<2606.2607 (CVE-2026-58113) CVSS Vendor Equipment Vulnerabilities v3 6.1 Siemens Siemens Teamcenter Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Background Critical Infrastructure Sectors: Critical Manufacturing, Information Technology Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-58113 Affected applications do not properly encode user-supplied…
EUCOMVulns & exploitsICS / OTCritical infrastructure
2026-09-15 · Rapid7 blog · score 7
Overview On September 14, 2026, Cisco published a security advisory for CVE-2026-76461 , a critical SQL injection vulnerability affecting Cisco AsyncOS Software for Cisco Secure Email Gateway. The vulnerability has a reported CVSS v3.1 base score of 9.8 and could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on an affected appliance. Cisco Secure Email Gateway, formerly known as IronPort Email Security Appliance, is an enterprise email security product that inspects inbound and outbound email for threats including phishing, malware, spam, and business email compromise. Because affected gateways process externally delivered email as part of their normal operation, exploitation does not require access to an administrative interface or authentication. An attacker can reportedly trigger the vulnerability by sending a specially crafted email through a vulnerable gateway. CVE-2026-76461 was added to CISA's Known Exploited Vulnerabilities ( KEV ) catalog on the same day as the vendor disclosed the vulnerability, indicating that CVE-2026-76461 was exploited as a zero-day prior to disclosure. Cisco noted that their PSIRT became aware of…
NORTHCOMVulns & exploitsSocial engineeringMalware & toolingUnited States
2026-09-15 · DefenseScoop · score 7.5
Drafts of the fiscal 2027 NDAA include provisions to repeal existing laws that established the Space Development Agency.
SPACECOMNORTHCOMSpace & SATCOMUnited States
2026-09-15 · CISA Cybersecurity Advisories · score 7.75
View CSAF Summary Siemens Reyrolle 7SR5 Before V2.70 is affected by multiple vulnerabilities. Siemens has released a new version for Reyrolle 7SR5 and recommends to update to the latest version. The following versions of Siemens Reyrolle 7SR5 are affected: Reyrolle 7SR5 vers:intdot/<2.70 (CVE-2024-42384, CVE-2024-42385, CVE-2024-42386, CVE-2024-42391, CVE-2024-42392, CVE-2026-62645, CVE-2026-62646, CVE-2026-62647, CVE-2026-62648, CVE-2026-62649, CVE-2026-62650, CVE-2026-62652, CVE-2026-62653, CVE-2026-62654) CVSS Vendor Equipment Vulnerabilities v3 9.8 Siemens Siemens Reyrolle 7SR5 Integer Overflow or Wraparound, Improper Neutralization of Delimiters, Use of Out-of-range Pointer Offset, Missing Authentication for Critical Function, Insufficient Entropy, Improper Input Validation, Out-of-bounds Write, Allocation of Resources Without Limits or Throttling, Authentication Bypass Using an Alternate Path or Channel, Insertion of Sensitive Information Into Debugging Code, Download of Code Without Integrity Check Background Critical Infrastructure Sectors: Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2024-42384 Integer…
EUCOMNORTHCOMVulns & exploitsICS / OTCritical infrastructure
2026-09-15 · CISA Cybersecurity Advisories · score 7.75
View CSAF Summary Schneider Electric is aware of a vulnerability in its SCADAPack x70 products. The SCADAPack 47x, SCADAPack 47xi, SCADAPack 47xd, SCADAPack 470R and SCADAPack 57x products are Remote Terminal Units that provide communication capabilities for remote monitoring and control. Failure to apply the mitigations provided below may increase the risk of unauthorized access to RTU configuration through the Secure Lock functionality, potentially resulting in a loss of confidentiality. The following versions of Schneider Electric SCADAPack x70 Products are affected: SCADAPack 47x vers:all/* (CVE-2026-81861) SCADAPack 47xi vers:all/* (CVE-2026-81861) SCADAPack 47xd vers:all/* (CVE-2026-81861) SCADAPack 470R vers:all/* (CVE-2026-81861) SCADAPack 57x vers:all/* (CVE-2026-81861) SCADAPack 3xx vers:all/* (CVE-2026-81861) SCADAPack 32 vers:all/* (CVE-2026-81861) CVSS Vendor Equipment Vulnerabilities v3 6.5 Schneider Electric Schneider Electric SCADAPack x70 Products Insufficiently Protected Credentials Background Critical Infrastructure Sectors: Critical Manufacturing, Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: France Vulnerabilities Expand All +…
EUCOMVulns & exploitsICS / OTPolicy & guidance
2026-09-15 · Dark Reading · score 8
A likely North Korean advanced persistent threat (APT) group used a previously undocumented Linux espionage toolkit to compromise load balancers, gain access to communications, and further exploit networks.
PACOMNORTHCOMAPT & espionageROKNorth Korea
2026-09-15 · The Record (Recorded Future) · via TJFSCC Daily · score 8
China's spy chief identified Anthropic’s Claude Mythos and OpenAI’s GPT-5.5-Cyber as signs of what he called a “disruptive upgrade” in cyber capabilities, increasing the speed and potential weaponization of vulnerability discovery and malware development.
PACOMNORTHCOMAI & cyberVulns & exploitsMalware & toolingChinavia TJFSCC Daily
2026-09-15 · The Register — security · score 8.5
Gartner sees huge amounts of technical debt paid down, and better scanning that could make software safer sooner
PACOMNORTHCOMVulns & exploitsRansomwareSupply chainAustralia
2026-09-15 · The Hacker News · score 9
Cybersecurity agencies in the United States, the United Kingdom, and the Netherlands have detailed a Windows malware that they say Iran's intelligence service uses to spy on dissidents, journalists, and activists around the world. The malware is controlled via the Telegram messaging app and can copy a target's emails and chat messages, take screenshots, and activate the microphone to record
CENTCOMEUCOMMalware & toolingApps & devicesAPT & espionageIranUnited States
2026-09-15 · The Register — security · score 9.25
'Enemies of the regime' on notice
CENTCOMEUCOMMalware & toolingApps & devicesAPT & espionageIranUnited States
2026-09-15 · CISA Cybersecurity Advisories · score 9.5
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to access live video and sensitive device information, enable unauthorized services, execute arbitrary code, modify device operation, and recover stored credentials. The following versions of CareCam CM2507 are affected: HMT.CM2507 Firmware v251211.1507 (CVE-2026-88259, CVE-2026-84398, CVE-2026-84400, CVE-2026-81305, CVE-2026-85478, CVE-2026-85497, CVE-2026-81321) CVSS Vendor Equipment Vulnerabilities v3 7.5 CareCam CareCam CM2507 Missing Authentication for Critical Function, Empty Password in Configuration File, Inclusion of Functionality from Untrusted Control Sphere, Use of Password Hash With Insufficient Computational Effort, Cleartext Storage of Sensitive Information Background Critical Infrastructure Sectors: Commercial Facilities Countries/Areas Deployed: Worldwide Company Headquarters Location: China Vulnerabilities Expand All + CVE-2026-88259 CareCam CM2507 IP cameras do not require authentication for access to its network video streaming service. An unauthenticated attacker with network access to the affected device could retrieve live camera video. View CVE Details Affected…
PACOMVulns & exploitsSupply chainPolicy & guidanceChina
2026-09-15 · CISA Known Exploited Vulnerabilities · score 10.25
Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability. Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs vulnerability that could allow an unauthenticated, remote attacker to gain unauthorized access to the affected device by bypassing the web-based management interface. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Due 2026-09-19.
NORTHCOMVulns & exploitsCloud & identityPolicy & guidanceUnited StatesKEV
2026-09-15 · CISA Known Exploited Vulnerabilities · score 10.25
Acronis Backup Incorrect Default Permissions Vulnerability. Acronis Backup plugin for cPanel & WHM and extension for Plesk contains an incorrect default permissions vulnerability that could allow for privilege escalation. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Due 2026-09-19.
NORTHCOMVulns & exploitsPolicy & guidanceBreach & leaked dataUnited StatesKEV
2026-09-15 · CISA Known Exploited Vulnerabilities · score 11
Google Pixel Improper Authorization Vulnerability. Google Pixel devices contain an improper authorization vulnerability in the cellular modem. A logic error may allow an attacker to bypass permission checks and escalate privileges. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Due 2026-09-19.
NORTHCOMVulns & exploitsApps & devicesPolicy & guidanceUnited StatesKEV
2026-09-15 · The Register — security · score 12.75
Security firm Infoblox shines light on malicious infrastructure lurking beneath illegal gambling sites
PACOMNORTHCOMAPT & espionageScams & fraudMalware & toolingChinaNorth Korea
2026-09-14 · Canadian Centre for Cyber Security · score 3
Vulns & exploits
2026-09-14 · Dark Reading · score 3
CVE-2026-85706 is a path traversal vulnerability with a 10 out of 10 CVSS score, affecting both GitLab Community Edition and Enterprise Edition instances.
Supply chainVulns & exploits
2026-09-14 · CIS / MS-ISAC advisories · score 3.5
A vulnerability has been discovered in GitLab, which could allow disclosure of sensitive data. GitLab GitLab is a DevOps platform that provides source code management, CI/CD pipelines, issue tracking, and collaboration tools in a single application for software development teams. Successful exploitation of this vulnerability could allow for path traversal, leading to disclosure of potentially sensitive information such SSH keys, database credentials, deploy tokens. Depending on the sensitive information retrieved via this technique, the attacker may gain further access to the appliance or systems.
Vulns & exploits
2026-09-14 · Canadian Centre for Cyber Security · score 4.75
Apps & devicesVulns & exploits
2026-09-14 · CIS / MS-ISAC advisories · score 4.75
Multiple vulnerabilities have been discovered in MikroTik Routers, the most severe of which could allow for admin hijacking . MikroTik routers are network devices that use the RouterOS operating system to provide advanced routing, firewall, wireless, VPN, bandwidth management, and network security features for homes, businesses, and internet service providers. Successful exploitation of the most severe of these vulnerabilities could allow an attacker to take full control of a device without authentication.
Vulns & exploitsApps & devices
2026-09-14 · SANS Internet Storm Center · score 5.25
Today, Apple released its annual update across all its operating systems. With that, Apple not only released new features but also patched 261 different vulnerabilities. This is the most vulnerabilities Apple has ever patched, but the increase is not as significant as other vendors&#;x26;#;39; "post-AI" patch releases.
Vulns & exploitsBreach & leaked dataApps & devices
2026-09-14 · Canadian Centre for Cyber Security · score 5.5
NORTHCOMVulns & exploitsStandards & complianceUnited States
2026-09-14 · The Record (Recorded Future) · via TJFSCC Daily · score 5.5
The pro-Ukraine hacktivist group Hacking Cat has evolved from carrying out website defacements and data leaks to more sophisticated and destructive attacks on Russian targets, researchers said.
EUCOMMalware & toolingHacktivism & DDoSRansomwareRussiaUkrainevia TJFSCC Daily
2026-09-14 · Yonhap News (English) · via TJFSCC Daily · score 6
The expanded Criminal Act, which now covers espionage activities benefiting othe...
PACOMAPT & espionageROKvia TJFSCC Daily
2026-09-14 · Dark Reading · score 6.25
The notorious Russian threat group is spreading an upgraded version of the botnet malware, which the FBI disrupted in 2022.
EUCOMNORTHCOMVulns & exploitsMalware & toolingSandwormRussiaUnited States
2026-09-14 · Rapid7 blog · score 6.25
Overview On September 10, 2026, GitLab published a critical patch release for GitLab Community Edition (CE) and Enterprise Edition (EE). The release addresses CVE-2026-85706 , a critical path traversal vulnerability ( CWE-22 ) in the repository commits API with a CVSSv3.1 score of 10.0 . According to GitLab, improper path confinement and missing authentication enforcement could allow an unauthenticated user to read arbitrary files from an affected GitLab server under certain conditions. On September 11, 2026, CVE-2026-85706 was added to the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. CISA set a remediation due date of September 14, 2026, for affected Federal Civilian Executive Branch agencies and marked the vulnerability as subject to forensic triage requirements under Binding Operational Directive 26-04. Organizations running affected self-managed GitLab instances should remediate CVE-2026-85706 on an emergency basis, outside of normal patch cycles. Mitigation guidance A vendor-supplied update is available to remediate CVE-2026-85706. Organizations running affected…
NORTHCOMVulns & exploitsPolicy & guidanceSupply chainUnited States
2026-09-14 · The Register — security · score 6.5
CISA confirms active exploitation as watchTowr spots miscreants probing internet-facing servers
NORTHCOMVulns & exploitsMalware & toolingPolicy & guidanceUnited States
2026-09-14 · The Japan Times · via TJFSCC Daily · score 7
The U.S. has been working to expand its role in building subsea cables, which carry nearly all international internet traffic.
PACOMNORTHCOMTelecom & cablesChinaUnited Statesvia TJFSCC Daily
2026-09-14 · CISA Cybersecurity Advisories · score 7.5
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-76461 Cisco Secure Email Gateway SQL Injection Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability…
NORTHCOMVulns & exploitsPolicy & guidanceBreach & leaked dataUnited States
2026-09-14 · The Hacker News · score 8.25
A Chinese threat actor has been attributed to a spear-phishing campaign that exploits recently patched security flaws in Google Chrome and Microsoft Windows to deliver a malicious JavaScript backdoor called GRIMWEDGE. Volexity, which is tracking the threat cluster under the moniker UTA0560, said the activity targeted multiple non-governmental organizations (NGOs) on September 1, 2026. "The
PACOMVulns & exploitsSocial engineeringMalware & toolingChina
2026-09-14 · The Register — security · score 9
Beijing’s response is to ‘firmly grasp technological sovereignty’ and broad regulations
PACOMNORTHCOMVulns & exploitsRansomwareBreach & leaked dataChina
2026-09-14 · South China Morning Post (China) · via TJFSCC Daily · score 9
Germany’s military counter-intelligence agency, known as MAD, has warned of a growing threat from hybrid attacks and the use of recruited contract agents, or low-level agents, saying Germany is a “prioritised target of Russian espionage activities”. According to the agency’s annual report released on Monday, it cited Germany’s geostrategic position in Europe and Nato the expansion of the Bundeswehr and the introduction of new weapons systems as reasons for the heightened targeting. “The hybrid...
EUCOMPACOMAPT & espionageChinaRussiavia TJFSCC Daily
2026-09-14 · Check Point Research · score 10.5
For the latest discoveries in cyber research for the week of 14th Setpember, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES IDScan.net, a US identity verification provider, has disclosed a data breach after detecting unauthorized access on September 1. Exposed data included names and government identification numbers, while a criminal marketplace advertised a […]
PACOMNORTHCOMVulns & exploitsBreach & leaked dataPolicy & guidanceShinyHuntersAustraliaNew Zealand
2026-09-13 · Recorded Future — Insikt · score 5.5
Move from reactive defense to a proactive security mindset. Learn how proactive threat intelligence identifies and neutralizes threats.
Vulns & exploitsBreach & leaked dataCloud & identity
2026-09-13 · The Register — security · score 10
RIP, you won't be mourned
NORTHCOMPACOMVulns & exploitsICS / OTSupply chainChinaUnited States
2026-09-13 · CISA Known Exploited Vulnerabilities · score 10.25
CISA added Cisco Secure Email Gateway CVE-2026-76461 (CVSS 9.8) to KEV the day Cisco disclosed it.
Per Rapid7, a crafted email gives root command execution pre-authentication on an internet-facing gateway.
Recommend confirming with the S6 that Secure Email Gateway and ISE are patched.
GLOBALvulnerability_exploitationedge_deviceUnited StatesKEVAI-curated
2026-09-12 · South China Morning Post (China) · via TJFSCC Daily · score 8.75
Beijing has urged the United States to “immediately stop all espionage activities” targeting Chinese companies, warning that it had “firm resolve and abundant means” to retaliate after a senior CIA official defended spying on China’s artificial intelligence (AI) and chip sectors. The call from China’s Ministry of Commerce comes just two weeks ahead of President Xi Jinping’s visit to Washington, where AI and advanced technologies – the new battleground in the US-China rivalry – are expected to be...
PACOMNORTHCOMAPT & espionageSupply chainChinaUnited Statesvia TJFSCC Daily
2026-09-12 · U.S. Space Force · score 10.25
The U.S. Department of War, in partnership with defense ministries from 10 international partners, has signed Amendment Three to the multilateral Wideband Global SATCOM Memorandum of Understanding.
NORTHCOMSPACECOMPolicy & guidanceSpace & SATCOMUnited States
2026-09-11 · Canadian Centre for Cyber Security · score 3
Vulns & exploits
2026-09-11 · Canadian Centre for Cyber Security · score 3
Vulns & exploits
2026-09-11 · Canadian Centre for Cyber Security · score 3.25
Vulns & exploits
2026-09-11 · Canadian Centre for Cyber Security · score 3.25
Vulns & exploits
2026-09-11 · Dark Reading · score 3.5
The Dubai-based threat detection startup uses artificial intelligence tools to scan billions of IP addresses to find exposed assets, leaked data, and zero-day vulnerabilities.
NORTHCOMVulns & exploitsBreach & leaked data
2026-09-11 · Canadian Centre for Cyber Security · score 4
Vulns & exploitsSupply chain
2026-09-11 · Rapid7 blog · score 4.25
This One Goes to Sixteen! Another banger from Metasploit with sixteen new modules, including ten exploit modules, with five on the CISA KEV list. Cisco, Papercut, Sonicwall, Jetbrains, and Langflow all have exploit modules, and not to be outdone, we even have a Metasploit scanner to watch the watchers! New module content (16) Elasticsearch ingest-attachment Apache Tika XFA XXE Local File Read Authors: Bourbon Offensive Security Services and Jean-Marie Bourbon Type: Auxiliary Pull request: #21739 contributed by kmkz Path: scanner/http/elasticsearch_tika_xfa_xxe CVE reference: CVE-2025-66516 Description: Adds an auxiliary scanner module for CVE-2025-54988/CVE-2025-66516. The module validates an XML External Entity (XXE) vulnerability in Apache Tika's XFA parser exposed through the Elasticsearch attachment ingest processor. SPIP Unauthenticated Blind SQLi via Date Field Escaping Bypass Authors: Benoit Hua, Franck Chevalier, Julien Voisin, and ka3n1x Type: Auxiliary Pull request: #21791 contributed by jvoisin Path: scanner/http/spip_annee_sqli Description: Adds modules/auxiliary/scanner/http/spip_annee_sqli.rb which exploits a blind SQL injection in SPIP's date column escaping logic.…
NORTHCOMVulns & exploitsStandards & complianceUnited States
2026-09-11 · Nextgov/FCW — cybersecurity · score 4.5
Records released for the 25th anniversary of 9/11 also describe intelligence assessments of extremist websites helping recruit fighters and spread chemical and biological weapons information.
NORTHCOMCENTCOMRansomwareUnited StatesCanada
2026-09-11 · Canadian Centre for Cyber Security · score 5.25
NORTHCOMVulns & exploitsStandards & complianceUnited States
2026-09-11 · CERT/CC Vulnerability Notes (Carnegie Mellon SEI) · score 5.5
Overview An out-of-bounds (OOB) memory access vulnerability involving unchecked array indexing has been identified in the exllamav3_ext compute unified device architecture ( CUDA ) extension. Successful exploitation can lead to an immediate denial of service or application instability. This vulnerability is tracked as CVE-2026-84286. Description An OOB memory access vulnerability exists in the exllamav3_ext module due to insufficient input validation. When the kernel parameter K is set to 0 in a crafted input, the extension generates a negative array index, resulting in a CUDA illegal memory access.s. The root cause is a missing bounds check in the kernel-table dispatch process. The checkpoint-derived block index ( cbi ) is used to access a fixed 24-entry array without confirming that either K or cbi fall within safe limits. Impact Primary impacts include Denial of Service (DoS) through process crashes and potential unstable execution states within applications utilizing the library. Solution The vendor has addressed this vulnerability in the main repository. Users are advised to update their installations or apply the fix from the merged pull request:…
NORTHCOMVulns & exploitsSupply chainHacktivism & DDoS
2026-09-11 · Canadian Centre for Cyber Security · score 5.75
NORTHCOMICS / OTVulns & exploits
2026-09-11 · Canadian Centre for Cyber Security · score 6
NORTHCOMCritical infrastructureVulns & exploitsStandards & compliance
2026-09-11 · Canadian Centre for Cyber Security · score 6.25
NORTHCOMVulns & exploitsSupply chainStandards & complianceUnited States
2026-09-11 · Canadian Centre for Cyber Security · score 6.25
NORTHCOMVulns & exploitsSupply chainStandards & complianceUnited States
2026-09-11 · Canadian Centre for Cyber Security · score 6.5
NORTHCOMVulns & exploitsSupply chainStandards & complianceUnited States
2026-09-11 · The Register — security · score 7
Swapping legal work for malware development ended in extradition and a guilty plea
EUCOMNORTHCOMRansomwareMalware & toolingBreach & leaked dataUkraineUnited States
2026-09-11 · CISA Cybersecurity Advisories · score 7.25
CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-42016 JFrog Artifactory Incorrect Authorization Vulnerability CVE-2026-42018 JFrog Artifactory Improper Authentication Vulnerability CVE-2026-84869 ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check…
NORTHCOMVulns & exploitsPolicy & guidanceBreach & leaked dataUnited States
2026-09-11 · CISA Cybersecurity Advisories · score 7.25
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-85706 GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt…
NORTHCOMVulns & exploitsPolicy & guidanceBreach & leaked dataUnited States
2026-09-11 · Nextgov/FCW — cybersecurity · score 10.75
Former intelligence officials describe a nation better equipped to disrupt terrorist plots, but still wrestling with the costs of its response and how to prevent the next crisis under escalating technology threats.
NORTHCOMCYBERCOMAPT & espionageUnited StatesChina
2026-09-10 · Canadian Centre for Cyber Security · score 3
Vulns & exploits
2026-09-10 · Canadian Centre for Cyber Security · score 3
Vulns & exploits
2026-09-10 · Canadian Centre for Cyber Security · score 4
Vulns & exploitsHacktivism & DDoS
2026-09-10 · Canadian Centre for Cyber Security · score 4
Vulns & exploitsSupply chain
2026-09-10 · Canadian Centre for Cyber Security · score 4.25
Vulns & exploitsStandards & compliance
2026-09-10 · Canadian Centre for Cyber Security · score 4.25
Vulns & exploitsCloud & identity
2026-09-10 · CERT/CC Vulnerability Notes (Carnegie Mellon SEI) · score 4.75
Overview An incorrect permissions assignment vulnerability in the amwrtdrv.sys kernel driver, included with AOMEI Backupper 8.4.0, allows an unprivileged local user to perform arbitrary writes to the physical disk. When Secure Boot is disabled, this can be leveraged to execute arbitrary UEFI-level code before the operating system loads. This allows an attacker to bypass OS-level security controls, including HVCI, EDR solutions, and Microsoft Defender. The attack may also enable capture of BitLocker Volume Master Key (VMK) material, depending on the system's BitLocker configuration. Description AOMEI Backupper from AOMEI International Network Limited is designed to provide backup and disaster recovery services. It also helps individuals and businesses to create system images, disk clones, and file backups. AOMEI Backupper is available as a Windows application and can be integrated into enterprise backup workflows or directly used by end users. CVE-2026-12780 : An Incorrect Permission Assignment for Critical Resource (CWE-732) vulnerability in the amwrtdrv.sys kernel driver used by AOMEI Backupper 8.4.0 allows an unprivileged local attacker to achieve UEFI-level arbitrary code…
NORTHCOMVulns & exploitsSupply chain
2026-09-10 · Zscaler ThreatLabz · score 5.25
IntroductionIn June 2026, Zscaler ThreatLabz identified a new malware family, tracked as SloppyRAT, that is likely leveraged by a ransomware-related threat actor. ThreatLabz observed SloppyRAT being delivered through a multi-stage ClickFix infection chain. The malware supports a variety of features including a large number of built-in PowerShell-like commands, encrypted code blocks, EtherHiding for command-and-control (C2) resolution through the Polygon JSON-RPC protocol, and multiple anti-analysis techniques. Beyond SloppyRAT’s capabilities, the malware is notable because the codebase includes numerous software flaws, which suggest that it is still under development. Key TakeawaysIn June 2026, ThreatLabz identified SloppyRAT, a new malware family likely used in ransomware attacks to establish a foothold for lateral movement.SloppyRAT uses several techniques to make analysis more difficult, including encrypted code blocks that are decrypted and executed at runtime, as well as junk code and indirect system calls.SloppyRAT has an EtherHiding implementation as a backup channel for C2, which can be used to hinder disruption efforts.SloppyRAT uses certificate pinning to prevent…
NORTHCOMRansomwareMalware & toolingSocial engineering
2026-09-10 · CIS / MS-ISAC advisories · score 6
Multiple vulnerabilities have been discovered in Ivanti products, the most severe of which could allow for arbitrary code execution. Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution in the context of the system. Ivanti Endpoint Manager Mobile (Ivanti EPMM) is a mobile management software engine that enables mobile device, application, and content management. Ivanti Neurons is a cloud-based automation platform that unifies IT operations and security management into a single system of record. Ivanti Sentry is an in-line gateway that manages, encrypts, and secures traffic between the mobile device and back-end enterprise systems. Depending on the privileges associated with the system, an attacker could then install programs; view, change, or delete data. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.
Vulns & exploitsApps & devicesCloud & identity
2026-09-10 · The Register — security · score 6
Have I Been Pwned logs leaked records spanning patients, staff, and providers
NORTHCOMBreach & leaked dataRansomwareSupply chainShinyHunters
2026-09-10 · Dark Reading · score 6.25
Threat actors are leveraging Microsoft's Graph API to identify lucrative targets, then passing their access to extortion groups like ShinyHunters.
OPSEC & personal securityCloud & identityRansomwareShinyHunters
2026-09-10 · CISA Cybersecurity Advisories · score 6.75
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to disclose information, brute-force hashes, or run arbitrary code in a browser session. The following versions of AVEVA Pipeline Integrity Monitor are affected: AVEVA Pipeline Integrity Monitor <=2025_SP1_P1_build_7.1.9580.8513 (CVE-2026-81821, CVE-2026-81822, CVE-2026-81823, CVE-2026-81824) CVSS Vendor Equipment Vulnerabilities v3 8.4 AVEVA AVEVA Pipeline Integrity Monitor Use of Hard-coded Cryptographic Key, Use of a Broken or Risky Cryptographic Algorithm, Missing Authorization, Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: United Kingdom Vulnerabilities Expand All + CVE-2026-81821 The vulnerability, if exploited, could allow a miscreant with read access to PIMBoards project files to decrypt and view sensitive information. View CVE Details Affected Products AVEVA Pipeline Integrity Monitor Vendor: AVEVA Product Version: AVEVA Pipeline Integrity Monitor: <=2025_SP1_P1_build_7.1.9580.8513 Product Status: known_affected…
EUCOMVulns & exploitsCritical infrastructureSupply chainUK
2026-09-10 · CISA Cybersecurity Advisories · score 6.75
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to exfiltrate date or cause a denial-of-service condition. The following versions of NextGen Healthcare Mirth Connect are affected: Mirth Connect <=v4.7.1 (CVE-2026-82583, CVE-2026-78224, CVE-2026-82578) CVSS Vendor Equipment Vulnerabilities v3 8.3 NextGen Healthcare NextGen Healthcare Mirth Connect Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), Improper Restriction of XML External Entity Reference Background Critical Infrastructure Sectors: Healthcare and Public Health Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-82583 NextGen Connect (Mirth Connect) versions 4.7.1 and earlier allow an authenticated user to execute arbitrary SQL through a Database Connector API, which could result in disclosure of stored credentials for connected systems, arbitrary file write, and a denial-of-service condition. View CVE Details Affected Products NextGen Healthcare Mirth Connect Vendor: NextGen Healthcare Product Version: NextGen Healthcare Mirth Connect: <=v4.7.1 Product Status: known_affected…
NORTHCOMVulns & exploitsCritical infrastructureSupply chainUnited States
2026-09-10 · CISA Cybersecurity Advisories · score 7
View CSAF Summary Successful exploitation of this vulnerability could allow an authenticated remote attacker to write past the end of a heap allocation when Orthanc decodes an attacker-supplied PNG or JPEG image, resulting in a crash of the Orthanc process and a denial-of-service condition. The following versions of Orthanc DICOM Server are affected: Orthanc DICOM Server <1.13.0. (CVE-2026-87020) CVSS Vendor Equipment Vulnerabilities v3 8.1 Orthanc Orthanc DICOM Server Integer Overflow or Wraparound Background Critical Infrastructure Sectors: Healthcare and Public Health Countries/Areas Deployed: Worldwide Company Headquarters Location: Belgium Vulnerabilities Expand All + CVE-2026-87020 An integer overflow in a specified pitch and buffer-size computation leads to a heap out-of-bounds write when Orthanc decodes an attacker-supplied PNG. View CVE Details Affected Products Orthanc DICOM Server Vendor: Orthanc Product Version: Orthanc DICOM Server: <1.13.0. Product Status: known_affected Remediations Mitigation Orthanc recommends users update to v1.13.0. https://orthanc.uclouvain.be/downloads/index.html Relevant CWE: CWE-190 Integer Overflow or Wraparound Metrics CVSS Version Base…
Vulns & exploitsCritical infrastructureSupply chain
2026-09-10 · CISA Cybersecurity Advisories · score 7.25
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-67277 MikroTik RouterOS Missing Authentication for Critical Function Vulnerability CVE-2026-86060 MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the…
NORTHCOMVulns & exploitsPolicy & guidanceBreach & leaked dataUnited States
2026-09-10 · Canadian Centre for Cyber Security · score 8
NORTHCOMVulns & exploitsPolicy & guidanceSupply chainUnited StatesCanada
2026-09-10 · CISA Cybersecurity Advisories · score 8.5
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to device information or cause a denial-of-service condition. The following versions of ST Engineering iDirect iQ-Series Terminals (Update A) are affected: Evolution iQ‑Series terminals <=4.5.2.1 (CVE-2026-38059, CVE-2026-38057, CVE-2026-38056, CVE-2026-38058) 3315‑Series terminals <=4.5.2.1 (CVE-2026-38059, CVE-2026-38057, CVE-2026-38056, CVE-2026-38058) 9‑Series terminals <=4.5.2.1 (CVE-2026-38059, CVE-2026-38057, CVE-2026-38056, CVE-2026-38058) CVSS Vendor Equipment Vulnerabilities v3 8.8 ST Engineering iDirect ST Engineering iDirect iQ-Series Terminals Missing Authentication for Critical Function, Cross-Site Request Forgery (CSRF), Missing Authorization, Exposure of Sensitive System Information to an Unauthorized Control Sphere Background Critical Infrastructure Sectors: Communications, Defense Industrial Base, Energy, Government Services and Facilities, Transportation Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-38059 The iDirect iQ200 exposes the /api/identity and /api/ REST…
NORTHCOMVulns & exploitsBreach & leaked dataPolicy & guidanceUnited States
2026-09-10 · CyberScoop · via TJFSCC Daily · score 9.5
The report details a Russian-aligned espionage campaign against more than 20 organizations, an exploit foundry run by Chinese undergraduates and ShinyHunters-affiliated breaches, among other disrupted operations.
PACOMEUCOMAPT & espionageBreach & leaked dataShinyHuntersChinaRussiavia TJFSCC Daily
2026-09-10 · CISA Known Exploited Vulnerabilities · score 10.25
ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability. ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to transfer and execute files through an active remote session without authorization or host confirmation. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Due 2026-09-14.
NORTHCOMVulns & exploitsPolicy & guidanceBreach & leaked dataUnited StatesKEV
2026-09-10 · CISA Known Exploited Vulnerabilities · score 10.25
JFrog Artifactory Incorrect Authorization Vulnerability. JFrog Artifactory contains an incorrect authorization vulnerability that leads to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Due 2026-09-25.
NORTHCOMVulns & exploitsPolicy & guidanceBreach & leaked dataUnited StatesKEV
2026-09-10 · CISA Known Exploited Vulnerabilities · score 10.25
JFrog Artifactory Improper Authentication Vulnerability. JFrog Artifactory contains an improper authentication vulnerability that could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Due 2026-09-25.
NORTHCOMVulns & exploitsPolicy & guidanceBreach & leaked dataUnited StatesKEV
2026-09-10 · CISA Known Exploited Vulnerabilities · score 10.25
GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability. GitLab Community Edition and Enterprise Edition contains a path traversal vulnerability that allows an unauthenticated user to read arbitrary files due to an improper path confinement and missing authentication enforcement in the repository commits API. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Due 2026-09-14.
NORTHCOMVulns & exploitsPolicy & guidanceBreach & leaked dataUnited StatesKEV
2026-09-10 · The Register — security · score 12.5
Human operator: don't touch CIS orgs. AI agents: look a squirrel!
EUCOMPACOMAI & cyberVulns & exploitsAPT & espionageRussiaChina
2026-09-10 · The Register — security · score 14.25
Everyone from ShinyHunters to Russian freelancers is in on the illicit model fun
EUCOMPACOMAPT & espionageScams & fraudRansomwareAPT29ShinyHuntersRussiaChina
2026-09-09 · Proofpoint Threat Insight · score 2.5
NORTHCOMVulns & exploits
2026-09-09 · ESET WeLiveSecurity · score 2.75
LLM-based code scanners won’t help attackers build a nuclear weapon, but that refusal could work in their favor
AI & cyberMalware & tooling
2026-09-09 · Recorded Future — Insikt · score 3
AI agents don't fail from weak reasoning. They fail due to the disconnected and untrustworthy operational world in which they act. Find out why the world representation you give an agent matters more than the model you pick.
AI & cyberVulns & exploits
2026-09-09 · Canadian Centre for Cyber Security · score 3.5
NORTHCOMVulns & exploits
2026-09-09 · CIS / MS-ISAC advisories · score 3.75
A vulnerability has been discovered in SAP Extended Passport (EPP) Processing that could allow for remote code execution. SAP Extended Passport (EPP) Processing is a core system data structure and tracing mechanism within SAP Kernel code used to track, log, and monitor end-to-end communication across distributed SAP and non-SAP landscapes. It is created automatically when a new user session opens and travels via communication protocols like RFC (Remote Function Call) and HTTP from the client to the server. Onapsis explained that, because EPP processing is shared kernel code, the vulnerability is reachable from the SAP GUI layer every end user connects to, and from the RFC layer that links SAP systems to one another. The bug is remotely exploitable without authentication and exists by default in a range of SAP components. Successful exploitation of this vulnerability may allow a remote attacker to run arbitrary operating system commands on the SAP host with SAP administrative privileges, leading to a total compromise of the underlying SAP business data and processes.
NORTHCOMVulns & exploits
2026-09-09 · Canadian Centre for Cyber Security · score 5.5
NORTHCOMVulns & exploitsStandards & complianceUnited States
2026-09-09 · Canadian Centre for Cyber Security · score 5.5
NORTHCOMVulns & exploitsStandards & complianceUnited States
2026-09-09 · Canadian Centre for Cyber Security · score 5.5
NORTHCOMVulns & exploitsStandards & complianceUnited States
2026-09-09 · Canadian Centre for Cyber Security · score 7
NORTHCOMVulns & exploitsCloud & identitySupply chainUnited StatesCanada
2026-09-09 · Canadian Centre for Cyber Security · score 7.5
NORTHCOMVulns & exploitsCloud & identityHacktivism & DDoSUnited States
2026-09-09 · CISA Advisories · via TJFSCC Daily · score 7.5
CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2025-25249 Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability CVE-2026-19490 Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability CVE-2026-87491 Google Chromium V8 Out of Bounds Write Vulnerability CVE-2026-20079 Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring…
NORTHCOMVulns & exploitsPolicy & guidanceBreach & leaked dataUnited Statesvia TJFSCC Daily
2026-09-09 · Proofpoint Threat Insight · score 8
PACOMVulns & exploitsAPT & espionageChina
2026-09-09 · CyberScoop · via TJFSCC Daily · score 8
Multiple China-aligned threat groups exploited the defects quickly to target various organizations. Proofpoint said the activity is ongoing and expects it to widen.
PACOMVulns & exploitsAPT & espionageChinavia TJFSCC Daily
2026-09-09 · The Register — security · score 9
Calif says AI helped turn a VoIP memory bug into cross-platform RCE before Tencent shut it down
PACOMNORTHCOMVulns & exploitsApps & devicesMalware & toolingChina
2026-09-09 · Volexity · score 10
On September 1, 2026, Volexity’s Network Security Monitoring (NSM) service detected a spear-phishing campaign from a Chinese threat actor it tracks as UTA0560 targeting customers at multiple non-governmental organizations (NGOs). […]
PACOMNORTHCOMVulns & exploitsMalware & toolingSocial engineeringLinen / Violet TyphoonChina
2026-09-09 · CISA Known Exploited Vulnerabilities · score 10.25
MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability. MikroTik RouterOS contains an improper neutralization of argument delimiters in a command vulnerability which allows an attacker to change the trusted RouterOS policy mask, leading to privilege escalation. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Due 2026-09-13.
NORTHCOMVulns & exploitsPolicy & guidanceBreach & leaked dataUnited StatesKEV
2026-09-09 · CISA Known Exploited Vulnerabilities · score 10.25
MikroTik RouterOS Missing Authentication for Critical Function Vulnerability. MikroTik RouterOS contains a missing authentication for critical function vulnerability which allows kernel memory disclosure and denial of service in the btest service. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Due 2026-09-13.
NORTHCOMVulns & exploitsPolicy & guidanceBreach & leaked dataUnited StatesKEV
2026-09-09 · Cisco Talos · score 11
Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco’s Secure Firewall Management Center (FMC) Software.
EUCOMNORTHCOMVulns & exploitsAPT & espionageRansomwareSandwormQilinRussiaUnited States
2026-09-09 · The Register — security · score 12
Mind the patch gap, please and thank you
PACOMNORTHCOMVulns & exploitsAPT & espionageAI & cyberLinen / Violet TyphoonChinaSE Asia
2026-09-08 · Dark Reading · score 2.5
Two separate attacks demonstrate how threat actors are finding new ways to compromise organizations by using the popular social engineering tactic.
NORTHCOMSocial engineering
2026-09-08 · JPCERT/CC (English) · score 2.75
Vulns & exploits
2026-09-08 · JPCERT/CC (English) · score 3
Vulns & exploits
2026-09-08 · Rapid7 blog · score 3.25
Overview While conducting research into a recent N-able N-central authentication bypass vulnerability ( CVE-2026-18577 ), Rapid7 Labs discovered two new vulnerabilities affecting the latest version of N-central. When chained together, these two vulnerabilities allow a remote unauthenticated attacker to bypass authentication and create a new attacker-controlled System administrator account on an affected server. CVE ID Description CWE CVSSv4 CVE-2026-86206 Semicolon/Forwarded access-control bypass CWE-791 6.9 (Medium) CVE-2026-86207 UserTwoFactorLogin authentication bypass CWE-305 7.7 (High) Both CVE-2026-86206 and CVE-2026-86207 have been patched by the vendor via N-central 2026.3 Hotfix 3. Product description N-able N-central is an enterprise-grade Remote Monitoring and Management (RMM) platform designed for Managed Service Providers (MSPs) and IT departments to monitor, manage, and secure complex, large-scale networks from a centralized dashboard. Credit These vulnerabilities were discovered by Stephen Fewer, Senior Principal Security Researcher at Rapid7 , and are being disclosed in accordance with Rapid7's vulnerability disclosure policy . Technical analysis CVE-2026-86206…
Vulns & exploitsSupply chain
2026-09-08 · CIS / MS-ISAC advisories · score 3.25
Multiple vulnerabilities have been discovered in Microsoft products, the most severe of which could allow for remote code execution. Successful exploitation of the most severe of these vulnerabilities could result in an attacker gaining the same privileges as the logged-on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.
Vulns & exploits
2026-09-08 · Check Point Research · score 4
Research by: Alexey Bukhteyev Key Takeaways Introduction Over the past several years, AI assistants have moved far beyond text generation. Modern systems can execute code, install additional dependencies, analyze user files, and access data through connected services. These capabilities significantly increase the practical value of LLMs, but they also change the security model: protecting user […]
NORTHCOMAI & cyberVulns & exploits
2026-09-08 · CIS / MS-ISAC advisories · score 5
Multiple vulnerabilities have been discovered in Adobe products, the most severe of which could allow for arbitrary code execution. Adobe Experience Manager (AEM) is an enterprise-grade digital experience platform that combines content management, digital asset management, and digital enrollment into a single cloud-native solution. Adobe ColdFusion is a commercial rapid web application development platform used to build, deploy, and scale dynamic enterprise web and mobile applications. Adobe Photoshop is a professional raster graphics editor used to create, edit, and manipulate digital images. Adobe Illustrator is an industry-standard vector graphics editor and design software used to create infinitely scalable artwork, logos, icons, typography, and complex illustrations. Adobe Animate is computer animation and multimedia authoring software. Adobe Commerce is a flexible, enterprise-level e-commerce platform built on top of Magento technology that helps businesses create and manage online stores. Adobe Acrobat Reader is a free software application used to view, print, sign, share, and annotate PDF (Portable Document Format) files. Adobe Campaign Classic is an enterprise marketing…
NORTHCOMVulns & exploitsCloud & identity
2026-09-08 · Krebs on Security · score 5.5
Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever. Microsoft says artificial intelligence is helping to speed the discovery of vulnerabilities, but security experts warn that many organizations already are struggling to prioritize the more human-intensive endeavor of testing and deploying so many fixes each month.
Vulns & exploitsMalware & toolingSupply chain
2026-09-08 · CERT/CC Vulnerability Notes (Carnegie Mellon SEI) · score 5.5
Overview A Server-Side Request Forgery (SSRF) vulnerability exists in Ascensio System SIA's ONLYOFFICE ownCloud integration plugin (version 9.12). The plugin’s backend endpoint does not adequately validate the user‑supplied document server URL before initiating outbound connections. An authenticated administrator can exploit this flaw to coerce the ownCloud server into issuing arbitrary network requests to attacker‑controlled destinations. Description The ownCloud ecosystem delivers a platform for enterprise file collaboration, providing capabilities for storing, syncing, and sharing data across devices. Ascensio System SIA's ONLYOFFICE provides a connector that integrates with ownCloud, enabling users to open and edit files directly within the cloud storage environment. When configuring the ONLYOFFICE document server within ownCloud, the plugin accepts a document server parameter and attempts to verify the supplied URL by initiating a connection directly from the ownCloud server. As detailed in CVE-2026-84282 , the application does not restrict or sanitize this parameter, allowing an authenticated administrator to provide arbitrary URLs, including internal network hosts or…
Vulns & exploitsSupply chainCloud & identity
2026-09-08 · CERT/CC Vulnerability Notes (Carnegie Mellon SEI) · score 6
Overview Skullcandy Dime 3 wireless earbuds, running firmware version 1.0.0.28, accept a new Bluetooth Classic (BR/EDR) pairing request from an unpaired device without requiring the earbuds to be placed into pairing mode or requiring any physical confirmation or interaction from the owner. Description The Skullcandy Dime 3 (Model S2DCW) wireless earbuds, running firmware version 1.0.0.28, accept a new Bluetooth Classic (BR/EDR) pairing request from a previously unpaired device without the device being placed into pairing mode by the owner and without physical confirmation on the earbuds. The device's Bluetooth PnP modalias identifies the chipset vendor as Airoha Technology Corp. (Bluetooth SIG company ID 0x0094). This vulnerability was previously disclosed in CVE-2025-20701 and is described as: In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. An attacker is required to be within Bluetooth radio range to the target earbuds, but no prior pairing, physical access, or…
Vulns & exploitsApps & devicesSupply chain
2026-09-08 · The Register — security · score 6.5
Claims follow scrutiny over monitors installing adware without user consent
NORTHCOMApps & devicesVulns & exploitsOPSEC & personal security
2026-09-08 · Cisco Talos · score 7.5
Microsoft has released its monthly security update for September 2026, which includes 973 vulnerabilities affecting a range of products, including 113 that Microsoft marked as "critical."
Vulns & exploitsCloud & identitySpace & SATCOM
2026-09-08 · Cisco Talos · score 7.5
Cisco Talos is tracking a cryptocurrency-stealing campaign that abuses the Google Visualization API for command and control (C2), retrieving obfuscated JavaScript from a publicly published Google Sheets document and injecting it into the victim's browser session.
NORTHCOMSPACECOMSocial engineeringDPRK & crypto theftMalware & tooling
2026-09-08 · The Register — security · score 7.5
Researchers disclosed the cross-account trick the same day rogue agents exploited another zero-day for admin access
NORTHCOMSPACECOMAI & cyberVulns & exploitsBreach & leaked data
2026-09-08 · CISA Advisories · via TJFSCC Daily · score 7.5
CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-75650 Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability CVE-2026-81963 Microsoft Windows Link Following Vulnerability CVE-2026-85880 Microsoft Windows Heap-Based Buffer Overflow Vulnerability CVE-2026-86218 N-able N-central Static Code Injection Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD…
NORTHCOMVulns & exploitsPolicy & guidanceBreach & leaked dataUnited Statesvia TJFSCC Daily
2026-09-08 · CERT/CC Vulnerability Notes (Carnegie Mellon SEI) · score 9.5
Overview The UEFI Shell program may expose raw memory access capabilities that, if present in platform firmware for debugging or advanced support use cases, could be abused to undermine UEFI Secure Boot protections. When the UEFI Shell is included in SPI flash, an attacker with the ability to modify UEFI boot configuration may be able to create multiple boot option entries and bypass controls intended to prevent the UEFI Shell from launching while Secure Boot is enabled. This could allow an attacker to modify the pre-boot environment and execute unauthorized software during system startup. Description The Unified Extensible Firmware Interface (UEFI) is a firmware specification that defines the interface between a computing platform's hardware and operating system (OS) during the early boot process before the operating system is loaded. UEFI Secure Boot helps ensure that only trusted and digitally signed software is executed during these early stages of platform initialization. The TianoCore EDK II project provides an open-source reference implementation of the UEFI and Platform Initialization (PI) specifications. The project includes the UEFI Shell , which provides command-line…
NORTHCOMSPACECOMSupply chainVulns & exploitsPolicy & guidance
2026-09-08 · CISA ICS Advisories · score 10
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to take full control of the device. The following versions of CareCam Pro IP Cameras are affected: ANJIA AJL33PC0801 Firmware linux_linux_202008261138_svn13796_/_Bootloader_U-Boot_2010.06_compiled_2020-08-26 (CVE-2026-85083) CVSS Vendor Equipment Vulnerabilities v3 6.8 CareCam CareCam Pro IP Cameras Use of Hard-coded Credentials Background Critical Infrastructure Sectors: Commercial Facilities Countries/Areas Deployed: Worldwide Company Headquarters Location: China Vulnerabilities Expand All + CVE-2026-85083 The ANJIA AJL33PC0801 IP camera uses a hard-coded credential for bootloader authentication. An attacker with physical access to the device may leverage this weakness to gain privileged bootloader access, allowing unauthorized modification of firmware and system configuration and potentially resulting in complete device compromise. View CVE Details Affected Products CareCam Pro IP Cameras Vendor: CareCam Product Version: CareCam ANJIA AJL33PC0801 Firmware: linux_linux_202008261138_svn13796_/_Bootloader_U-Boot_2010.06_compiled_2020-08-26 Product Status: known_affected Remediations Mitigation…
PACOMNORTHCOMVulns & exploitsSupply chainPolicy & guidanceChina
2026-09-08 · CISA Known Exploited Vulnerabilities · score 10.25
Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability. Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability involving an alternate path or channel. When the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy), an unauthenticated remote threat actor may be able to bypass authentication. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Due 2026-09-12.
NORTHCOMVulns & exploitsPolicy & guidanceBreach & leaked dataUnited StatesKEV
2026-09-08 · CISA Known Exploited Vulnerabilities · score 10.25
Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability. Fortinet FortiOS, FortiSwitchManager, and FortiSASE contain a heap-based buffer overflow vulnerability that allows an attacker to execute unauthorized code or commands via specially crafted packets. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Due 2026-09-12.
NORTHCOMVulns & exploitsPolicy & guidanceBreach & leaked dataUnited StatesKEV
2026-09-08 · CISA Known Exploited Vulnerabilities · score 10.25
Google Chromium V8 Out of Bounds Write Vulnerability. Google Chromium V8 contains an out of bounds write vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Due 2026-09-23.
NORTHCOMVulns & exploitsPolicy & guidanceBreach & leaked dataUnited StatesKEV
2026-09-08 · CISA Known Exploited Vulnerabilities · score 10.25
Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability. Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain an authentication Bypass using an alternate path or channel vulnerability that could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Due 2026-09-12.
NORTHCOMVulns & exploitsCloud & identityPolicy & guidanceUnited StatesKEV
2026-09-07 · CIS / MS-ISAC advisories · score 3.25
Multiple vulnerabilities have been discovered in Dell Secure Connect Gateway, the most severe of which could allow for arbitrary code execution. Dell Secure Connect Gateway is an enterprise monitoring and connection software for Dell infrastructure. Successful exploitation of the most severe of these vulnerabilities could result in an attacker gaining the same privileges as the logged-on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.
Vulns & exploits
2026-09-07 · Recorded Future — Insikt · score 5.5
In August 2026, Insikt Group® identified 73 high-impact vulnerabilities that should be prioritized for remediation, 43 of which had a Very Critical Recorded Future Risk Score. This represents a 14% decrease from last month.
NORTHCOMVulns & exploitsSupply chainBreach & leaked dataUnited States
2026-09-07 · Check Point Research · score 5.5
For the latest discoveries in cyber research for the week of 7th Setpember, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Thomson Reuters, a global information and technology company, has disclosed a breach of its C-Track court case-management platform affecting courts across 11 US states and Canada. An unauthorized party obtained C-Track files […]
NORTHCOMVulns & exploitsBreach & leaked dataAI & cyberCanada
2026-09-07 · CISA Known Exploited Vulnerabilities · score 10.25
Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability. Adobe Commerce and Magento Open Source contain an improper neutralization of special elements used in a template engine vulnerability that could allow an attacker to execute arbitrary code. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Due 2026-09-11.
NORTHCOMVulns & exploitsSupply chainPolicy & guidanceUnited StatesKEV
2026-09-07 · CISA Known Exploited Vulnerabilities · score 10.25
Microsoft Windows Link Following Vulnerability. Microsoft Windows Update Stack contains a link following vulnerability that allows a local attacker to escalate privileges locally up to SYSTEM. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Due 2026-09-22.
NORTHCOMVulns & exploitsPolicy & guidanceBreach & leaked dataUnited StatesKEV
2026-09-07 · CISA Known Exploited Vulnerabilities · score 10.25
N-able N-central Static Code Injection Vulnerability. N-able N-central contains a static code injection vulnerability that could allow for pre-authentication remote code execution. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Due 2026-09-11.
NORTHCOMVulns & exploitsPolicy & guidanceBreach & leaked dataUnited StatesKEV
2026-09-07 · CISA Known Exploited Vulnerabilities · score 10.25
Microsoft Windows Heap-Based Buffer Overflow Vulnerability. Microsoft Windows Advanced Local Procedure Call contains a heap-based buffer overflow vulnerability that allows an attacker to elevate privileges locally. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Due 2026-09-22.
NORTHCOMVulns & exploitsPolicy & guidanceBreach & leaked dataUnited StatesKEV

Force Protection 0 items What Guardians, Airmen, civilians, and families need to know personally: scams, social engineering, apps and devices, OPSEC, breaches of consumer services, official guidance.

2026-10-06 · SANS Internet Storm Center · score 3.75
It seems that a trend started&#xe2;&#x80;&#xa6; I continue my journey discovering more RMM ("Remote Management & Monitoring") tools abused by threat actors! A few days ago, I wrote a diary[ 1 ] about ScreenConnect used in the wild. Today, I found another one.
NORTHCOMSocial engineeringCloud & identity
2026-10-06 · BleepingComputer · score 4
A new campaign targeting ad account managers uses fake ChatGPT, Gemini, Claude, and Perplexity sites that steal login credentials and multi-factor authentication (MFA) codes through browser-in-browser attacks. [...]
NORTHCOMOPSEC & personal securityAI & cyber
2026-10-06 · Malwarebytes Labs · score 4.5
ASOS customers received a push notification regarding a breach of the company. Here's what we know so far.
NORTHCOMBreach & leaked dataSupply chainCloud & identity
2026-10-06 · The Guardian (World) · via TJFSCC Daily · score 5
Angus Taylor’s drastic cuts to graduate visas aim to end a citizenship pathway, but universities body says changes will make Australia less competitive Get our new political email , free app or daily news podcast The Coalition’s migration plan risks breaching Australia’s free trade agreement with India, signed by the former Morrison government, allowing Indian students to stay and work for up to four years after completing their studies. Angus Taylor on Tuesday announced plans to cut net overseas migration to 100,000 for the first two years of a Coalition government and up to 160,000 in year four, in a plan which would abolish temporary graduate visas, make major cuts to international student, bridging and temporary protection visas, and halve humanitarian places.
PACOMBreach & leaked dataIndiaAustraliavia TJFSCC Daily
2026-10-06 · Malwarebytes Labs · score 5.25
Domino's is warning customers by email that their accounts have been compromised in a credential stuffing attack.
NORTHCOMScams & fraudBreach & leaked dataCloud & identity
2026-10-06 · BleepingComputer · score 5.25
UK fashion retailer ASOS confirmed a data breach Tuesday after hackers sent unauthorized push notifications through its mobile app while claiming to have stolen customer data from the company's Snowflake environment. [...]
EUCOMBreach & leaked dataPolicy & guidanceCloud & identityUK
2026-10-06 · Malwarebytes Labs · score 5.75
Facebook users are reporting receiving a message with a fake Facebook Marketplace listing that has their name as the seller.
NORTHCOMScams & fraudSocial engineeringBreach & leaked data
2026-10-06 · The Guardian (World) · via TJFSCC Daily · score 6.75
Watchdog examining whether company carried out adequate risk assessment as required by Online Safety Act Mark Zuckerberg’s Meta is under investigation for a potential breach of the UK’s digital safety laws after launching a Snapchat-style feature on Instagram. The communications watchdog, Ofcom, is investigating whether the $1.9tn (£1.4tn) company infringed the Online Safety Act (OSA) by failing to carry out adequate checks on whether its Instagram Instants product could show illegal content or be accessed by children.
EUCOMSPACECOMBreach & leaked dataOPSEC & personal securityUKvia TJFSCC Daily
2026-10-06 · The Record (Recorded Future) · score 7.75
The personal data of at least 68,000 people was reportedly exposed in breaches of at least seven financial institutions, with officials saying they believe a Chinese cybersecurity tool was used to hack the banks’ systems.
PACOMNORTHCOMAI & cyberBreach & leaked dataROKChina
2026-10-05 · The Hacker News · score 2.75
A new type of ClickFix attack is using compromised websites to trick users into executing a malicious payload cached in a web browser's cache. "Instead of downloading and executing remote payloads like the typical attack pattern, in this attack, the websites pre-fetch a script payload into the browser cache disguised as a PNG file," the Microsoft Threat Intelligence team said in a post on X.
NORTHCOMSocial engineering
2026-10-05 · The Record (Recorded Future) · score 3.25
Several mysteries surround what appeared to be an unauthorized push notification sent to customers of London-based clothing company ASOS.
EUCOMPolicy & guidanceUK
2026-10-05 · The Hacker News · score 3.25
Unauthorized parties have gained access to the names, addresses, and personal identification numbers of about 8.8 million people, living and dead, in Denmark's national population register, the country's digitalization ministry said on October 5. They used a private Danish company's lawful right to look up records in the Central Person Register (CPR). The ministry has told people never to
EUCOMNORTHCOMPolicy & guidance
2026-10-05 · The Record (Recorded Future) · score 3.5
Denmark is investigating a data breach affecting approximately 8.8 million people after unauthorized users gained access to its national population register.
EUCOMBreach & leaked dataPolicy & guidance
2026-10-05 · The Record (Recorded Future) · score 3.75
Ukraine’s largest grocery store chain, ATB, confirmed that it was hit by a cyberattack after hackers posted an extortion demand on its website.
EUCOMBreach & leaked dataRansomwareUkraine
2026-10-05 · The Japan Times · via TJFSCC Daily · score 4.25
An OpenAI prototype sought access to a government health statistics portal, sidestepping restrictions to breach a section hosting private files.
PACOMBreach & leaked dataAustraliavia TJFSCC Daily
2026-10-05 · Politico Europe · via TJFSCC Daily · score 4.5
Fifty European Union lawmakers, including 46 women, have been the targets of deepfake pornography, according to new research released Monday. The number of women targeted by deepfake pornography — when generative AI is used to create sexually explicit depictions of people, often without their consent — means roughly one in six female members of the […]
EUCOMNORTHCOMAI & cyberSocial engineeringvia TJFSCC Daily
2026-10-05 · New York Times (Asia-Pacific) · via TJFSCC Daily · score 4.75
The president said there were signs that such models were used in recent attacks on several banks involving customer data. Police are investigating.
PACOMNORTHCOMBreach & leaked dataROKvia TJFSCC Daily
2026-10-05 · BleepingComputer · score 5.25
South Korea's Financial Services Commission (FSC) held an emergency meeting following a series of cyberattacks targeting financial institutions in the country. [...]
PACOMBreach & leaked dataAI & cyberROK
2026-10-05 · Infosecurity Magazine · score 5.25
Report Fraud says cybercrime revenue stemming from account takeover increased 417% annually
OPSEC & personal securityCloud & identityScams & fraud
2026-10-05 · The Straits Times (Asia) · via TJFSCC Daily · score 5.25
SYDNEY, Oct 6 - OpenAI and Anthropic told Australian parliament on Tuesday they would welcome laws requiring them to report data breaches carried out by their AI agents, acknowledging the decision to notify authorities was currently at their discretion.
PACOMBreach & leaked dataAI & cyberAustraliavia TJFSCC Daily
2026-10-05 · The Guardian (World) · via TJFSCC Daily · score 5.75
Company executive to acknowledge ‘more work to do to rebuild trust with the Australian people’ as ABC says copyright laws do not need changing Get our breaking news email , free app or daily news podcast OpenAI will use an appearance before a parliamentary committee to apologise again to Australia about the hack on Medicare last month, on the same day media and entertainment organisations argue weakening Australian copyright law for AI model training would leave artists as “roadkill”. Ahead of an appearance before the joint parliamentary committee hearing on artificial intelligence in Sydney on Tuesday afternoon, OpenAI released its opening statement in which the company apologises for its AI agents attacking a number of Australian government websites in June . The multibillion-dollar company notified the government via an email to a public-facing address three months after the breach.
PACOMAI & cyberBreach & leaked dataAustraliavia TJFSCC Daily
2026-10-05 · The Diplomat · via TJFSCC Daily · score 5.75
According to the FBI, American nationals lost around $50 million to one network of online scammers based in India.
PACOMNORTHCOMScams & fraudIndiaUnited Statesvia TJFSCC Daily
2026-10-05 · The Register — security · score 6.5
Intruders retrieved email addresses from superseded tech kept running for an internal system
NORTHCOMEUCOMBreach & leaked dataSupply chainPolicy & guidanceUK
2026-10-05 · South China Morning Post (China) · via TJFSCC Daily · score 6.5
China tried three times to persuade powerful families in northern Myanmar to shut down scam operations before Myanmar police carried out large-scale arrests in 2023, according to a new documentary broadcast on Chinese state television. The three-part documentary, jointly produced by China’s Ministry of Public Security and state broadcaster CCTV, began airing on Monday. It shows obstacles faced by Chinese authorities in pursuing criminal networks and scam groups operating in northern Myanmar...
PACOMScams & fraudChinaSE Asiavia TJFSCC Daily
2026-10-05 · BleepingComputer · score 6.75
Over the weekend, Japanese publishing giant Nikkei disclosed that unknown attackers recently breached two employee email accounts and used one to send thousands of phishing emails. [...]
PACOMNORTHCOMBreach & leaked dataSocial engineeringJapan
2026-10-05 · CNA (Asia) · via TJFSCC Daily · score 7.5
South Korea's police have launched a full-scale investigation into the hacking attacks against commercial banks that led to a breach of customers' personal information.
PACOMNORTHCOMBreach & leaked dataROKvia TJFSCC Daily
2026-10-05 · Inside Defense · via TJFSCC Daily · score 8.5
Monday, October 5, 2026 The Oct. 5, 2026 Defense Department instruction "establishes policy, assigns responsibilities, and provides procedures for the DOW Cyber Operations-Peculiar Awards (COPA) Program authorized by Section 1124a of Title 10 U.S.C. for covered Service members." Featured: Related Documents Tags: Cybersecurity
CYBERCOMPolicy & guidanceOPSEC & personal securityStrategy & organizationvia TJFSCC Daily
2026-10-05 · DefenseScoop · score 12
The RFI release comes amid growing concerns about North Korea’s drone arsenal.
PACOMEUCOMOPSEC & personal securitySupply chainROKNorth Korea
2026-10-04 · Bloomberg (Politics) · via TJFSCC Daily · score 4.75
US Attorney General Todd Blanche tells Bloomberg This Weekend that the Justice Department is expanding investigations into alleged election crimes ahead of the midterms, including noncitizen voting, and plans to deploy monitors to polling locations across the country. Speaking with Myles Miller, Blanche also discusses the department’s misconduct complaint against Minnesota federal judges, its review of the Federal Reserve headquarters renovation and the administration’s defense of its tariff authority. (Source: Bloomberg)
NORTHCOMScams & fraudUnited Statesvia TJFSCC Daily
2026-10-04 · The Register — security · score 6.5
Intruders retrieved email addresses from superseded tech kept running for an internal system
NORTHCOMEUCOMBreach & leaked dataSupply chainPolicy & guidanceUK
2026-10-04 · Malwarebytes Labs · score 6.75
A list of topics we covered in the week of September 28 to October 4 of 2026
NORTHCOMBreach & leaked dataApps & devicesAI & cyberUnited States
2026-10-04 · Focus Taiwan (CNA) · via TJFSCC Daily · score 6.75
Taipei, Oct. 5 (CNA) The Taipei District Prosecutors Office on Monday indicted Farxun E-commerce Co., Ltd. (華訊電能) and 25 people over an alleged fraudulent investment scheme that prosecutors said raised more than NT$219 million (US$6.89 million).
PACOMNORTHCOMScams & fraudTaiwanvia TJFSCC Daily
2026-10-04 · The Japan Times · via TJFSCC Daily · score 7
The men are believed to have been forced to take part in fraud at a base in Myanmar.
PACOMScams & fraudSE AsiaJapanvia TJFSCC Daily
2026-10-03 · BleepingComputer · score 2.75
The Technical University of Denmark (DTU) says information belonging to up to 200,000 users may have been exposed after hackers accessed its identity and access management system and downloaded a large amount of data. [...]
EUCOMBreach & leaked dataCloud & identity
2026-10-03 · Task & Purpose · via TJFSCC Daily · score 5.25
A mental health clinic owner used active duty service members, veterans and military families in a scheme that billed TRICARE $26 million.
NORTHCOMScams & fraudOPSEC & personal securityvia TJFSCC Daily
2026-10-03 · CNA (Asia) · via TJFSCC Daily · score 5.5
Authorities say that this is the Philippines' largest crackdown on illegal online gaming operators this year
PACOMScams & fraudPhilippinesvia TJFSCC Daily
2026-10-03 · The Straits Times (Asia) · via TJFSCC Daily · score 7
The government is investigating possible human trafficking-related offences by some of those arrested.
PACOMScams & fraudPhilippinesChinavia TJFSCC Daily
2026-10-03 · The Straits Times (Asia) · via TJFSCC Daily · score 7.75
The case came to light via an undercover investigation into a Telegram chat room where sexual images were circulated.
PACOMSocial engineeringAI & cyberApps & devicesROKvia TJFSCC Daily
2026-10-03 · The Hacker News · score 10.5
A new China-nexus cyber espionage group known as TA419 has been attributed to multiple credential phishing campaigns targeting artificial intelligence (AI) experts working for U.S. think tanks, universities, and legal sector organizations. The campaigns have impersonated prominent economists and AI policymakers, as well as a prominent Anthropic employee, to single out an AI policy expert at a
PACOMNORTHCOMSocial engineeringAPT & espionageTA419ChinaUnited States
2026-10-02 · Department of Justice press releases · score 3.75
A Brooklyn man pleaded guilty today to defrauding New York State Medicaid of approximately $65 million through claims for social adult day care services and home health care services that were not provided.
NORTHCOMScams & fraud
2026-10-02 · Inside Defense · via TJFSCC Daily · score 4.5
Defense Secretary Pete Hegseth is directing senior Pentagon leaders across multiple agencies to take steps meant to eliminate red tape in fielding counter unmanned aerial systems, according to a new memo. The memo lays out a series of “guiding principles” meant to accelerate the fielding of counter-drone systems, including giving commanders the authority to “weigh the risk” of using a system against the risk of doing nothing. If a request to use CUAS is denied, the denial must be submitted to the Pentagon’s counter-drone task force, Joint Interagency Task Force 401, along with the rationale, the memo states. The memo -- dated Sept. 28 and made public Friday -- also ensures that any “common system component, configuration, use case, test result, or mitigation measure” that has already been approved for use by a government agency will lead to an accelerated approval for commanders that request to use one of these same already-approved systems. The memo assigns JIATF 401 with the task of keeping a repository of technical data, common hazard assessments, approved mitigation measures and threat intelligence to accelerate the process of conducting weapons safety reviews of…
NORTHCOMPolicy & guidanceUnited Statesvia TJFSCC Daily
2026-10-02 · Inside Defense · via TJFSCC Daily · score 4.5
Defense Secretary Pete Hegseth is directing senior Pentagon leaders across multiple agencies to take steps meant to eliminate red tape in fielding counter unmanned aerial systems, according to a new memo. The memo lays out a series of “guiding principles” meant to accelerate the fielding of counter-drone systems, including giving commanders the authority to “weigh the risk” of using a system against the risk of doing nothing. If a request to use C-UAS is denied, the denial must be submitted to the Pentagon’s counter-drone task force, Joint Interagency Task Force 401, along with the rationale, the memo states. The memo -- dated Sept. 28 and made public Friday -- also ensures that any “common system component, configuration, use case, test result, or mitigation measure” that has already been approved for use by a government agency will lead to an accelerated approval for commanders that request to use one of these same already-approved systems. The memo assigns JIATF 401 with the task of keeping a repository of technical data, common hazard assessments, approved mitigation measures and threat intelligence to accelerate the process of conducting weapons safety reviews of…
NORTHCOMPolicy & guidanceUnited Statesvia TJFSCC Daily
2026-10-02 · Department of Justice press releases · score 5
Jael Watts, 45, of Alloway, New Jersey, and Luis Pino-Copete, 42, of Bogota, Colombia, were convicted by a jury of orchestrating a sweeping nationwide scheme to steal millions of dollars in federal program funds administered by the U.S. Department of Transportation (DOT) and the U.S. Department of Housing and Urban Development (HUD), designed to benefit elderly, disabled, and homeless Americans. This action is a part of the Trump Administration’s Task Force to Eliminate Fraud.
NORTHCOMSOUTHCOMScams & fraudUnited States
2026-10-02 · Inside Defense · via TJFSCC Daily · score 5
The Army will establish its own command focused on autonomy, acting Army Secretary Adam Telle announced today in a memo. The announcement comes two days after Defense Secretary Pete Hegseth said the Pentagon would establish a similar combatant command, and Telle's memo states the Army's version is being established under Hegseth's guidance. The Army’s command will be known as Army Futures and Autonomous Systems Command, or FASCOM, and the service’s vice chief will be responsible for setting it up, according to Telle’s memo . Meanwhile, the Army G-3/5/7 Force Management Directorate will align force structure in the areas of: Aviation Armor Fires Sustainment Engineering Training The Army’s acquisition chief will designate one service’s portfolio acquisition executives to be in charge of acquisition and rapid procurement authority for autonomous capabilities, according to Telle’s memo. The directive also tasks the acquisition chief with prioritizing the acquisition and fielding of autonomous fires, combat vehicles and watercraft resupply, breaching, reconnaissance, surveillance, target acquisition and manned/unmanned teaming by fiscal year 2028. Axios first reported the news Friday…
Policy & guidanceBreach & leaked dataUnited Statesvia TJFSCC Daily
2026-10-02 · The Straits Times (Asia) · via TJFSCC Daily · score 5.25
Information exposed in the breach included names, phone numbers, annual income and borrowing limits.
PACOMAI & cyberBreach & leaked dataROKvia TJFSCC Daily
2026-10-02 · The Guardian (World) · via TJFSCC Daily · score 6.25
Home affairs department orders all federal government agencies to conduct review of ‘legacy technology’ amid fallout from AI agent hacks Get our breaking news email , free app or daily news podcast The Australian government faces significant “tech debt” that could bring a big bill for taxpayers after the OpenAI Medicare breach , as government agencies will need to fortify their defences against future attacks by AI agents. This week, the home affairs department ordered all federal government agencies to conduct a “legacy technology stocktake” that requires a plan for each agency to “reduce legacy technology systems” to a level within the agency’s risk tolerance and appetite, the direction stated .
PACOMNORTHCOMAI & cyberBreach & leaked dataAustraliaUnited Statesvia TJFSCC Daily
2026-10-01 · Zscaler ThreatLabz · score 3.25
For years, ransomware coverage has tended to focus on two numbers: How many victims were hit and how much they paid. The ThreatLabz 2026 Ransomware Report points to a more consequential shift happening beneath the usual headlines. Attackers aren’t just hitting more targets, they’re taking more from victims. The volume of data exfiltrated by the top ransomware groups surged 275.8% year over year to 896.2 terabytes. That scale of theft doesn't happen in a vacuum. It requires access, reconnaissance, lateral movement, and staging—a chain of activity that gives defenders a real window to intervene. The question is whether their controls are positioned to close it in time. Terabyte Theft is the New StandardIt wasn’t long ago that attackers mostly targeted high-volume, low-storage textual and financial databases; the concept of a multi-terabyte breach was an outlier. Today it’s increasingly become the baseline of some of the most active ransomware groups.The 896.2 terabytes exfiltrated by the top 10 ransomware groups between April 2025 and March 2026 represents more than seven times the volume recorded during the 2023-2024 reporting period. Groups including Rhysida and Embargo aren’t…
RansomwareBreach & leaked data
2026-10-01 · The Record (Recorded Future) · score 3.25
An Iranian national accused by the U.S. of taking part in dozens of breaches involving the theft of academic data and intellectual property has been extradited from Montenegro.
NORTHCOMCENTCOMBreach & leaked dataUnited StatesIran
2026-10-01 · Cisco Talos · score 3.5
In this week’s edition, Amy reflects on the importance of prioritizing family and personal well-being over the pressure to remain constantly productive.
NORTHCOMSocial engineeringAI & cyber
2026-10-01 · ExecutiveGov · via TJFSCC Daily · score 4
GAO found seven of 18 Pentagon IT business programs reported fraud training gaps. Learn more about the watchdog's findings. The post GAO Recommends Fraud Risk Training for Pentagon IT Programs first appeared on Executive Gov .
Scams & fraudUnited Statesvia TJFSCC Daily
2026-10-01 · Yonhap News (English) · via TJFSCC Daily · score 4.25
SEOUL, Oct. 2 (Yonhap) -- Customer information of KB Kookmin Bank, a major comme...
PACOMBreach & leaked dataROKvia TJFSCC Daily
2026-10-01 · Yonhap News (English) · via TJFSCC Daily · score 4.25
SEOUL, Oct. 2 (Yonhap) -- Customer information of KB Kookmin Bank, a major comme...
PACOMBreach & leaked dataROKvia TJFSCC Daily
2026-10-01 · Bloomberg (Politics) · via TJFSCC Daily · score 4.75
Since the start of his second term, President Donald Trump has waged a fierce campaign to impose his will on the Federal Reserve, breaking with the modern convention of walling off the US central bank from political interference, at least publicly. Trump has sought to pressure the bank to cut interest rates and verbally attacked then-Fed chair Jerome Powell. He also has attempted to push a Fed governor, Lisa Cook, from her job, over unproven allegations of mortgage fraud.
NORTHCOMMalware & toolingScams & fraudUnited Statesvia TJFSCC Daily
2026-10-01 · Department of Justice press releases · score 5.25
Assistant Attorney General Colin M. McDonald of the Justice Department’s National Fraud Enforcement Division released a memorandum today regarding the Division’s corporate enforcement priorities.
Scams & fraudPolicy & guidance
2026-10-01 · Malwarebytes Labs · score 5.5
More than 70 fake crypto sites promise extra rewards for casting a vote, then prompt visitors to connect their wallets.
NORTHCOMSPACECOMSocial engineering
2026-10-01 · The Hacker News · score 5.5
Google has announced a new security measure that limits access to Android's accessibility services to verified applications classified as Accessibility Tools when Advanced Protection is enabled. With malicious Android applications abusing the API serving as the main conduit for malware and financial fraud, the tech giant said the move would block a major attack pathway. Advanced Protection is a
Apps & devicesMalware & toolingScams & fraud
2026-10-01 · Yonhap News (English) · via TJFSCC Daily · score 5.5
SEOUL, Oct. 1 (Yonhap) -- Personal information of around 25,000 customers has be...
PACOMBreach & leaked dataAI & cyberROKvia TJFSCC Daily
2026-10-01 · The Record (Recorded Future) · score 5.75
Two separate reports by cybersecurity companies highlight China-linked hacking operations, including a phishing campaign that impersonated Western experts.
PACOMSocial engineeringChina
2026-10-01 · Malwarebytes Labs · score 6
An AI shortcut can send confidential work data beyond your company’s control. Here’s how to get the benefits without taking unnecessary risks.
EUCOMNORTHCOMBreach & leaked dataAI & cyberVulns & exploitsUK
2026-10-01 · Infosecurity Magazine · score 6.25
CloudSyncD uses a fake Zoom installer to phish Mac passwords and launch a two-stage backdoor
NORTHCOMSPACECOMMalware & toolingSocial engineering
2026-10-01 · Malwarebytes Labs · score 6.25
Free Mobile customers received very convincing phishing emails after major data breach.
EUCOMNORTHCOMBreach & leaked dataSocial engineeringScams & fraud
2026-10-01 · Malwarebytes Labs · score 6.25
Free Mobile customers received very convincing phishing emails after major data breach.
EUCOMNORTHCOMBreach & leaked dataSocial engineeringScams & fraud
2026-10-01 · FTC Consumer Alerts · score 6.5
Kids face a lot of challenges online: from cyberbullying and scams to digitally altered deepfakes, like nudify apps that create fake nude photos and videos of real people. Even if you’ve had conversations with your child about online safety and sensitive topics like deepfakes, you probably know parents who are concerned about these topics, too. If so, consider using the FTC resources below to help you learn more and share with fellow parents.
NORTHCOMSocial engineeringOPSEC & personal securityAI & cyber
2026-10-01 · The Guardian (Australia) · via TJFSCC Daily · score 6.75
If a chatbot prompt like ‘find Australian medicine statistics’ results in a website breach, the responsibility does not lie with a piece of code The recent panic about a breach of Medicare computer security by an “AI agent” contrasts sharply with other recent cases such as the Telstra and Optus outages that left many Australians unable to reach Triple Zero . In those cases, no one blamed the computers involved. The mistakes were clearly sheeted home to the corporations that operated them. This wasn’t always the case. When the term “artificial intelligence” was coined some 70 years ago, the first mainframe computers (absurdly primitive by modern standards) were viewed with the same awe and concern as the AI agents of the present day. There were even “algorithms” (though the term wasn’t used in that way at the time) that were supposed to pick ideal dating matches.
PACOMNORTHCOMAI & cyberBreach & leaked dataAustraliavia TJFSCC Daily
2026-10-01 · Focus Taiwan (CNA) · via TJFSCC Daily · score 7
Taipei, Oct. 1 (CNA) Taiwan's Mainland Affairs Council (MAC) said Thursday that threats made by one or more persons impersonating a Taiwanese documentary distributor who brought a film about alleged forced organ harvesting in China to the country in 2024 appear to be a "new method" of Chinese transnational repression.
PACOMSocial engineeringChinaTaiwanvia TJFSCC Daily
2026-10-01 · Malwarebytes Labs · score 7.75
DMDC is notifying about 2.76 million people that attackers took SSNs, birth dates and service details from an unencrypted server, Oct 2025 to Jul 2026 (Malwarebytes, citing CNN). DOW offers 12 months of IDX monitoring.
Guardians and families may be affected; the data aids targeted phishing.
Consider a commander's call note: IDX, credit freeze, IRS IP PIN.
NORTHCOMBreach & leaked dataOPSEC & personal securityUnited StatesAI-curated
2026-10-01 · Focus Taiwan (CNA) · via TJFSCC Daily · score 8
Taipei, Oct. 2 (CNA) Taipei prosecutors on Friday indicted two people on charges of fraud, alleging they used Chinese tea seeds to produce camellia oil that was falsely labeled as being entirely made from Taiwanese tea seeds.
PACOMNORTHCOMScams & fraudTaiwanChinavia TJFSCC Daily
2026-10-01 · Infosecurity Magazine · score 8.25
TA419 posed as AI policymakers and economists to phish US AI policy experts' Microsoft 365 accounts
PACOMNORTHCOMSocial engineeringCloud & identityTA419China
2026-10-01 · The Register — security · score 11
Your invite to a fake AI policy advisory committee has strings attached
PACOMNORTHCOMSocial engineeringSupply chainCloud & identityTA419ChinaUnited States
2026-10-01 · CyberScoop · score 13.5
Cybersecurity firm Proofpoint said TA419 impersonated officials and AI industry figures in an effort to gain access to cloud accounts held by U.S. think tank, university and legal-sector experts.
PACOMNORTHCOMSupply chainSocial engineeringAPT & espionageTA419ChinaJapan
2026-09-30 · The Hacker News · score 4
Threat actors are abusing ChatGPT Custom GPTs to disguise them as legitimate product offerings and direct unsuspecting victims to malicious sites that employ ClickFix lures to deliver malware. Huntress, which observed the activity in late September 2026, said it marks the abuse of yet another feature in trusted artificial intelligence (AI) platforms. Prior campaigns have weaponized shared
Social engineeringMalware & toolingAI & cyber
2026-09-30 · Dark Reading · score 4.25
In yet another ClickFix-style campaign, threat actors abuse legitimate domains from OpenAI and Google to fool unsuspecting users.
Social engineeringMalware & toolingAI & cyber
2026-09-30 · Department of Justice press releases · score 4.5
Attorney General Todd Blanche, Department of Homeland Security Secretary Markwayne Mullin, and United States Attorney Daniel N. Rosen announced that a federal grand jury indicted ten defendants separately on September 24, 2026, for voter fraud. All defendants have made their initial appearances in federal court.
NORTHCOMScams & fraudUnited States
2026-09-30 · Inside Defense · via TJFSCC Daily · score 4.5
Wednesday, September 30, 2026 In a Sept. 30, 2026 memo, Defense Secretary Pete Hegseth establishes the Federal Operations for Resilience, Troop Resources, Energy, Supply, and Survivability initiative which "ensures that every major U.S. military installation generates its own independent power so bases remain lit, aircraft fly, and command centers stay online even if the civilian grid is taken down by cyberattack or sabotage." Featured: Related Documents Tags: SECDEF
NORTHCOMPolicy & guidanceUnited Statesvia TJFSCC Daily
2026-09-30 · BleepingComputer · score 5.25
The Pentagon's Defense Manpower Data Center (DMDC) is notifying millions of military service members that hackers stole their data after breaching the Pentagon's human resources management system in October 2025. [...]
Breach & leaked dataOPSEC & personal securityUnited States
2026-09-30 · Malwarebytes Labs · score 5.5
Who you are and where you live, work, and seek medical care could be revealed by data your car’s app shares with trackers.
NORTHCOMSupply chainOPSEC & personal securityBreach & leaked data
2026-09-30 · Malwarebytes Labs · score 5.75
Attackers copied sensitive court records, including more than 150,000 foster care reports, raising privacy and safety concerns for those Arizonans affected.
NORTHCOMSocial engineeringBreach & leaked dataRansomwareUnited States
2026-09-30 · Have I Been Pwned — breaches · score 6.25
In September 2026, Swiss medical device company Medela was the target of a ShinyHunters "pay or leak" extortion campaign . The data allegedly obtained in the breach was later published publicly and included 424k unique email addresses belonging predominantly to healthcare professionals, Medela staff and leads. The exposed data consisted primarily of corporate contact information, including names, physical addresses and phone numbers, with some records also containing associated support tickets. Data: Email addresses, Employers, Job titles, Names, Phone numbers, Physical addresses, Salutations, Support tickets.
Breach & leaked dataRansomwareShinyHunters
2026-09-30 · The Hacker News · score 6.25
ANY.RUN researchers traced a US-focused CSuite phishing campaign across 351 sandbox analyses, with 51% of submissions coming from the United States. Technology, manufacturing, government, and consulting organizations showed the highest exposure. By combining Microsoft 365 session theft with remote-access tool deployment, CSuite can turn a phishing incident into broader account compromise, fraud
NORTHCOMSocial engineeringCloud & identityScams & fraudUnited States
2026-09-30 · SANS Internet Storm Center · score 6.25
Threat Actors do not always use top-notch techniques or very complex malware to perform their attacks. Sometimes, they just abuse of existing applications...
NORTHCOMMalware & toolingSocial engineeringScams & fraudUnited States
2026-09-30 · CNA (Asia) · via TJFSCC Daily · score 6.5
South Korea has demanded an apology from Ukraine, saying that President Volodymyr Zelenskyy breached a secrecy agreement in revealing that Kyiv had transferred two captured North Korean soldiers to South Korea.
PACOMEUCOMBreach & leaked dataROKUkrainevia TJFSCC Daily
2026-09-30 · The Record (Recorded Future) · score 7.5
The Russian state-backed hacking group Star Blizzard has expanded its phishing operations this year, using a new technique that makes it easier to infect victims with malware.
EUCOMNORTHCOMAPT & espionageSocial engineeringMalware & toolingRussiaUkraine
2026-09-30 · Defense One · via TJFSCC Daily · score 7.75
Proofpoint identified phishing campaigns that borrowed prominent figures’ identities to approach U.S. policy researchers before attempting to steal access to their cloud accounts.
NORTHCOMPACOMSocial engineeringCloud & identityChinaUnited Statesvia TJFSCC Daily
2026-09-30 · GAO reports · score 8.75
What GAO Found The nation’s infrastructure relies on information systems to support its varied functions. This includes the networked Internet of Things (IoT) and operational technology (OT) devices that interact with the physical world, including in building maintenance systems and specialized equipment in hospitals and laboratories. Responsible federal agencies have issued guidance, best practices, and requirements to help agencies securely procure such devices. For example, the Office of Management and Budget (OMB) has issued requirements to ensure that agencies establish and maintain inventories of their networked devices and process IoT cybersecurity waivers. However, most agencies have not fully addressed OMB’s networked device requirements, which were established in December 2023 and updated in January 2025. Specifically, agencies’ initial inventories were required to be completed by September 2024. However, as of September 2026, of the 22 civilian Chief Financial Officer (CFO) Act agencies in GAO’s review, 15 had established an inventory, 11 were maintaining their inventories, and 10 had included all required information (such as asset description and software version)…
NORTHCOMPolicy & guidanceApps & devicesICS / OTUnited States
2026-09-30 · Nextgov/FCW — cybersecurity · score 12
According to Proofpoint, China-aligned TA419 posed as a former OSTP official, a former State economist and an Anthropic employee, inviting AI policy experts to a fake advisory committee and then phishing their Microsoft logins.
Staff who work with think tanks get the same invitations.
Be aware that known names can be spoofed; verify out of band.
PACOMNORTHCOMSocial engineeringCloud & identityAPT & espionageTA419ChinaUnited StatesAI-curated
2026-09-29 · The Record (Recorded Future) · score 3
A spokesperson for the court system told Recorded Future News that the incident did not involve ransomware and the hackers have not issued ransom demands for the stolen data as of Monday.
Breach & leaked dataRansomware
2026-09-29 · SecurityWeek · score 3
The data breach affects the Defense Manpower Data Center (DMDC), which maintains personnel records for the Department of Defense.
Breach & leaked dataUnited States
2026-09-29 · Department of Justice press releases · score 3.25
Today, the Justice Department’s National Fraud Enforcement Division announced the results of a surge of criminal enforcement actions targeting fraud in the Social Security Administration (SSA)’s benefits programs, including Supplemental Security Income (SSI).
Scams & fraud
2026-09-29 · SecurityWeek · score 3.5
The personalized versions of ChatGPT were used to impersonate legitimate products and trick users into executing PowerShell commands.
NORTHCOMSocial engineeringAI & cyber
2026-09-29 · The Hacker News · score 3.75
Cybersecurity researchers have identified a cluster of 101 npm packages that are used to trap developers into a WhatsApp group subscriber campaign dubbed PhantomSub. "The malicious packages abuse the 'Baileys' WhatsApp open source project to add the victims to groups without their consent," OX Security researchers Nir Zadok, Moshe Siman Tov Bustan, and Vitalii Chepurko said in a technical
NORTHCOMSupply chainApps & devices
2026-09-29 · AhnLab ASEC · score 3.75
Just because it’s a familiar tactic doesn’t mean you can let your guard down. A similar attack method using cryptocurrency rewards as bait has recently been identified again. This time, a case was confirmed in which the Node.Js-based malware JSCEAL was distributed through Facebook ads impersonating a cryptocurrency exchange. The threat actors lured users to […]
NORTHCOMMalware & toolingSocial engineering
2026-09-29 · BleepingComputer · score 4
A Vietnamese national was charged with money laundering for his role in a massive "pig butchering" scam, which defrauded a victim out of $16 million worth of cryptocurrency. [...]
Scams & fraudSE Asia scam compoundsSE Asia
2026-09-29 · The Record (Recorded Future) · score 4.75
The artificial intelligence giant acknowledged it botched its response to the incidents and should have done more to promptly notify and work with the Australian government in the days after it discovered the breaches.
PACOMBreach & leaked dataAustralia
2026-09-29 · Microsoft Security / MSTIC · score 4.75
Microsoft observed phishing campaigns that abused MSP360 RMM to deploy ScreenConnect, creating redundant remote-access channels for follow-on activity
NORTHCOMSocial engineeringPolicy & guidance
2026-09-29 · The Record (Recorded Future) · score 5
According to court documents, both men pleaded guilty to wire fraud, identity theft and access device fraud charges in June.
NORTHCOMScams & fraudCloud & identity
2026-09-29 · Malwarebytes Labs · score 5
A buyer chatted and negotiated with Muse, which shared the seller’s address and arranged a pickup. The seller knew nothing about it.
NORTHCOMAI & cyberOPSEC & personal securityCloud & identity
2026-09-29 · The Straits Times (Asia) · via TJFSCC Daily · score 5.5
Pyongyang warned it will retaliate if the South opens fire on its troops.
PACOMBreach & leaked dataNorth KoreaROKvia TJFSCC Daily
2026-09-29 · Yonhap News (English) · via TJFSCC Daily · score 5.5
SEOUL, Sept. 30 (Yonhap) -- South Korea blamed North Korea on Wednesday for last...
PACOMBreach & leaked dataROKNorth Koreavia TJFSCC Daily
2026-09-29 · Industrial Cyber · score 6
On September 22, Boston Scientific published the final summary of CrowdStrike’s investigation into the August 25 cyberattack that...
CENTCOMBreach & leaked dataSupply chainMalware & toolingIran
2026-09-29 · BleepingComputer · score 6.25
Two former members of the United States Air Force were sentenced to a combined 189 months in federal prison for their roles in a multi-year series of business email compromise (BEC) scams and phishing campaigns. [...]
NORTHCOMSocial engineeringScams & fraudUnited States
2026-09-28 · BleepingComputer · score 2.5
Infostealer logs exposed AI account credentials and sessions tied to more than 80,000 corporate domains, creating risks ranging from stolen conversations to LLMjacking. SOCRadar examines the growing market for stolen AI logins and how organizations can identify their exposure. [...]
Malware & toolingBreach & leaked data
2026-09-28 · SecurityWeek · score 3
The misuse and abuse of AI-generated voice is growing. Modulate’s intention is to allow real time detection and intervention.
Social engineeringAI & cyber
2026-09-28 · The Hacker News · score 3
A malicious MCP server could trick an application built on the official MCP Python SDK into handing over the OAuth credentials it uses to log in to a real service, the SDK's maintainers said in a security advisory. Affected versions sent the client secret, the authorization code, and the PKCE proof key to a token endpoint the attacker controlled. The fix is in versions 1.30.0 and
NORTHCOMCloud & identityAI & cyber
2026-09-28 · FTC Consumer Alerts · score 3.5
Health insurance scams happen year-round, but they pick up during Open Enrollment for Medicare and the Marketplace. If you’re looking to find a new plan, you might search online. But before you click on a search result, remember: scammers and dishonest businesses sometimes pay to appear at the top.
Scams & fraud
2026-09-28 · The Hacker News · score 4
A domain used as harmless placeholder text showed up in roughly 1,700 repositories. Then somebody registered it and started serving malicious lures. That is the kind of week this was: forgotten assumptions turning into live attack surface. Elsewhere, weak service accounts, old bugs, exposed systems, phishing kits, and strangely easy exploit paths kept doing useful work for attackers. Nothing
NORTHCOMAI & cyberSocial engineering
2026-09-28 · The Hacker News · score 4
RatHat's operators build and publish the Android banking trojan and control infected phones from a web console, according to security company Cleafy. Cleafy has traced nearly 100 deployments of that console since April 2026. It said this fits a malware-as-a-service model, in which each customer runs a separate copy. The console stores what the malware collects from each phone,
NORTHCOMMalware & toolingApps & devices
2026-09-28 · Huntress · score 4
Huntress researchers reveal how attackers are exploiting ChatGPT Custom GPTs to spread ClickFix lures and DLL-sideloaded malware. See the full breakdown.
Malware & toolingSocial engineeringAI & cyber
2026-09-28 · ABC News Australia · via TJFSCC Daily · score 4
Australia is looking to impose a dual notification requirement under tougher new standards enforced after OpenAI's breach of a Medicare website.
PACOMBreach & leaked dataAustraliavia TJFSCC Daily
2026-09-28 · The Diplomat · via TJFSCC Daily · score 4
The petition concerned the use of barcodes and QR codes on ballot papers, which some claimed could breach constitutional requirements for secret voting.
PACOMBreach & leaked dataSE Asiavia TJFSCC Daily
2026-09-28 · BleepingComputer · score 4.5
Japanese car-sharing service Times Car has confirmed that approximately 6.6 million user accounts were compromised in a cyberattack disclosed late last week. [...]
PACOMBreach & leaked dataJapan
2026-09-28 · Nikkei Asia · via TJFSCC Daily · score 4.75
PACOMScams & fraudSE Asiavia TJFSCC Daily
2026-09-28 · CyberScoop · score 5
One expert told CyberScoop that the announcement reflects industry recognition that after years of training models to behave safely or ethically, more outside controls are needed.
NORTHCOMSupply chainAI & cyberBreach & leaked dataUnited States
2026-09-28 · Politico Europe · via TJFSCC Daily · score 5.25
Uthmeier cited newly disclosed breaches of U.S. and Australian government websites, along with reports of OpenAI agents going rogue.
NORTHCOMPACOMBreach & leaked dataAustraliaUnited Statesvia TJFSCC Daily
2026-09-28 · Recorded Future — Insikt · score 6
How AI Changes Phishing, Impersonation, and Identity Verification
NORTHCOMSocial engineeringAI & cyberCloud & identity
2026-09-28 · Politico Europe · via TJFSCC Daily · score 6
OpenAI agents searched for health spending data, leading to Medicare breach
PACOMPolicy & guidanceBreach & leaked dataAustraliavia TJFSCC Daily
2026-09-28 · GAO reports · score 6.75
What GAO Found To meet its mission to protect the security of our nation and provide warfighters the assets they need, the Department of Defense (DOD) relies heavily on the use of information technology (IT). According to DOD’s Office of the Chief Information Officer (OCIO), the department planned to spend $10.3 billion on the 18 major IT business programs from fiscal years (FY) 2024 through 2026. The four largest programs account for 50 percent of the planned spending (see figure). The Department of Defense’s (DOD) Planned Costs for the Four Largest Information Technology (IT) Business Programs Compared to the Remaining 14 Selected Programs from Fiscal Year (FY) 2024 through FY 2026 To help determine whether operational programs are meeting their business or mission purpose, programs are required by the General Services Administration to identify and track a minimum of five performance metrics across the categories of customer satisfaction, strategic and business results, financial performance, and innovation. Of the 18 programs, 17 were operational. Of these, 15 identified the minimum required number of performance metrics in each category. However, the remaining two did not.…
Scams & fraudPolicy & guidance
2026-09-28 · Malwarebytes Labs · score 8.5
A fake iPhone Duo preorder page promises a $500 voucher. Open it on a vulnerable iPhone, and it tries to break in before you fill out the form.
NORTHCOMSPACECOMApps & devicesScams & fraudBreach & leaked data
2026-09-28 · CISA Known Exploited Vulnerabilities · score 10.25
CISA added Apple CoreGraphics CVE-2026-86950 to KEV on 28 Sep. Malwarebytes found a fake iPhone Duo preorder page that runs the DarkSword exploit chain on unpatched iPhones when opened.
Opening one link is enough on an unpatched personal iPhone.
Recommend updating Apple devices; real preorders open 16 Oct.
NORTHCOMApps & devicesVulns & exploitsScams & fraudUnited StatesKEVAI-curated
2026-09-28 · Malwarebytes Labs · score 10.5
An OpenAI agent bypassed internet restrictions and kept running after an alert. It's another case of AI misalignment no one can afford to ignore.
PACOMNORTHCOMAI & cyberBreach & leaked dataPolicy & guidanceChinaAustralia
2026-09-27 · The Guardian (Australia) · via TJFSCC Daily · score 4.25
Company behind Claude chatbot expected to attend separate Australian government hearing on AI next week Get our new political email , free app or daily news podcast The chief executive of Anthropic will turn down an invitation to appear at a Senate committee hearing on AI this week, in the wake of the revelation that OpenAI agents had breached Australian government websites. However, the company will make an appearance before another committee early next week. Sign up for Guardian Australia’s Politics, really newsletter here
PACOMBreach & leaked dataAustraliavia TJFSCC Daily
2026-09-27 · AhnLab ASEC · score 5
Recently, the AhnLab SEcurity intelligence Center (ASEC) identified a case of phishing emails that disguise themselves as project material purchase request forms. These emails impersonate employees of a specific company in Korea and trick recipients into opening a malicious XLS file attached to the email, which is disguised as a project material purchase request form. […]
PACOMSocial engineeringROK
2026-09-27 · Yonhap News (English) · via TJFSCC Daily · score 5.5
SEOUL, Sept. 28 (Yonhap) -- Fraudulent insurance claims increased by more than 9...
PACOMScams & fraudROKvia TJFSCC Daily
2026-09-27 · ABC News Australia · via TJFSCC Daily · score 5.5
Seoul accuses Ukraine of announcing the transfer of North Korean soldiers caught fighting for Russia to South Korea in breach of a non-disclosure agreement.
PACOMEUCOMBreach & leaked dataROKUkrainevia TJFSCC Daily
2026-09-27 · BleepingComputer · score 6.75
Cryptocurrency exchange Bitget has resumed Bitcoin withdrawals suspended after suspected North Korean hackers breached its systems last week and stole over $350 million. [...]
PACOMDPRK & crypto theftBreach & leaked dataNorth Korea
2026-09-27 · Malwarebytes Labs · score 8.5
A “shellfish and banana allergy” is among the details in medical records hackers showed reporters. They claim to hold records on thousands of FBI staff.
NORTHCOMBreach & leaked dataRansomwareOPSEC & personal securityCl0pShinyHuntersUnited States
2026-09-27 · The Register — security · score 9
Amid allegations that agents may have gone off the rails thousands of times, China set up some kind of agentic incident hotline
PACOMNORTHCOMSupply chainAI & cyberWorkforce & trainingAustraliaChina
2026-09-26 · ABC News Australia · via TJFSCC Daily · score 4
Labor, Coalition agree OpenAI's Medicare breach proves the need for Australia to secure "a seat at the AI table" by rolling out data centres nationally.
PACOMBreach & leaked dataAustraliavia TJFSCC Daily
2026-09-26 · The Hacker News · score 4.75
The Psychedelic Stealer malware distributed via compromised Ukrainian websites using ClickFix-style Cloudflare verification checks is part of a wider malware-as-a-service (MaaS) platform called Lunex. The new findings come from Ontinue, which described the activity as a four-stage attack chain aimed at targeting Ukrainian-speaking users. "The attack chain begins with a fake CAPTCHA page and
EUCOMNORTHCOMMalware & toolingSocial engineeringUkraine
2026-09-25 · Zscaler ThreatLabz · score 3.75
IntroductionIn August 2026, Zscaler ThreatLabz analyzed a phishing campaign that used fraudulent Google ads to target Ledger hardware wallet users. The ads redirected users through Google Cloud Storage and Vercel to a Google Sites page containing a phishing page impersonating Ledger in an iframe. During our analysis, the Vercel redirect appeared to change every 15-20 minutes. There, a fake device-verification process prompted users to enter their secret recovery phrases, which attackers could use to access their wallets without the physical devices.In this blog post, ThreatLabz examines the campaign’s infrastructure and the steps used to trick users into submitting their recovery phrases. Key TakeawaysIn August 2026, ThreatLabz discovered a campaign in which fraudulent Google ads targeting Ledger users appeared under a Google-verified advertiser profile. The ads routed users through Google Cloud Storage and Vercel to a Google Sites page that displayed the phishing content in an iframe.The Google Cloud Storage page redirected users to Vercel domains that appeared to change every 15-20 minutes during the observation period.A fake device-verification process asked users for their…
NORTHCOMSocial engineeringCloud & identity
2026-09-25 · New York Times (Asia-Pacific) · via TJFSCC Daily · score 4.75
The first known breach of a government website by rogue artificial intelligence agents has prompted global calls for more regulation of the technology.
PACOMBreach & leaked dataAustraliavia TJFSCC Daily
2026-09-25 · The Straits Times (Asia) · via TJFSCC Daily · score 5
There are calls for the Office of AI to help oversee testing and evaluations of new AI models.
PACOMBreach & leaked dataAI & cyberAustraliavia TJFSCC Daily
2026-09-25 · Dark Reading · score 5.75
Training human-resource managers in the latest tactics and warning signs goes a long way toward blunting the threat, but automated analysis can help even more.
Scams & fraudDPRK & crypto theftDPRK IT workers
2026-09-25 · Department of Justice press releases · score 5.75
A federal jury in Fort Worth convicted a Texas licensed professional counselor yesterday for his role in a $26 million health care fraud, kickbacks, and money laundering scheme.
NORTHCOMScams & fraudUnited States
2026-09-25 · ExecutiveGov · via TJFSCC Daily · score 6
SSA is using specialized AI for fraud detection and generative AI for administrative tasks. The post SSA Working With Federal Partners to Combat Deepfake, Other AI-Driven Fraud first appeared on Executive Gov .
NORTHCOMAI & cyberSocial engineeringScams & fraudUnited Statesvia TJFSCC Daily
2026-09-25 · The Register — security · score 8
More mockery and memes from the Dark Web Roast
NORTHCOMEUCOMSocial engineeringScams & fraudApps & devicesUnited StatesUK
2026-09-25 · The Register — security · score 8.25
Fake Windows apps for three US HR and payroll platforms install ScreenConnect remote access, according to Allure Security; none of the providers offers a desktop app.
Pay and HR systems hold Guardian and family financial data.
Consider using only bookmarked web portals for pay and HR.
NORTHCOMSPACECOMSocial engineeringMalware & toolingUnited StatesAI-curated
2026-09-25 · Department of Justice press releases · score 8.5
Cameron John Wagenius, 22, a former Army soldier who was most recently stationed in Texas, was sentenced today to 70 months in prison and ordered to pay $294,978 in restitution for conspiring to hack into telecommunications companies’ databases, access sensitive records, and extort the companies by threatening to release the stolen data unless ransoms were paid.
NORTHCOMRansomwareBreach & leaked dataTelecom & cablesUnited States
2026-09-25 · The Register — security · score 12.5
Familiar fingerprints point to Kim’s regime … to the surprise of nobody
PACOMNORTHCOMBreach & leaked dataPolicy & guidanceDPRK & crypto theftNorth KoreaROK
2026-09-24 · The Hacker News · score 2.5
A OnePlus 15 running the latest OxygenOS can be rooted by a malicious app the owner installs, one that asks for no special permissions. A researcher, Rasmus Moorats, chained two flaws in OnePlus's own software to gain root access, the highest level of control over an Android phone. OnePlus told him the same flaws affect many more of its own devices and those of OPPO, though it has not
Apps & devices
2026-09-24 · The Record (Recorded Future) · score 2.75
Ardit Kutleshi, 28, was extradited from his home country of Kosovo last year after prosecutors accused him and his older brother of running Rydox — an illicit platform used by cybercriminals to sell stolen personal information, illegal access to devices and other tools for carrying out fraud.
NORTHCOMScams & fraud
2026-09-24 · Department of Justice press releases · score 3.25
Ardit Kutleshi, 28, a Kosovar national, pleaded guilty to charges related to his creation and operation of Rydox, an illicit website and marketplace for cybercriminals to buy, sell and trade stolen personal information, and to access devices and other tools for carrying out cybercrime and fraud.
Scams & fraud
2026-09-24 · The Record (Recorded Future) · score 3.25
The healthcare firm Astrana warned regulators that hackers accessed confidential information by impersonating company personnel.
Breach & leaked dataSocial engineering
2026-09-24 · The Hacker News · score 3.25
The "third-party[.]com" domain, commonly used as a documentation placeholder, has been observed serving a ClickFix lure to Windows browsers while displaying a harmless decoy to other users. "third-party[.]com has been a generic documentation placeholder for years, the same role example.com plays," Manifold Security's Head of Research, Ax Sharma, said. "Unlike 'example[.]com,' third-party[.]com
NORTHCOMSupply chainSocial engineering
2026-09-24 · The Hacker News · score 3.75
AI coding agents are changing how quickly developers can build and ship software as well as how quickly credentials can become exposed. According to GitGuardian’s 2026 State of Secrets Sprawl Report, commits identified as AI-assisted are leaking secrets at approximately twice the rate of human-written ones. Most of the fastest-growing categories of leaked credentials are now connected to AI
Cloud & identityBreach & leaked dataAI & cyber
2026-09-24 · Nextgov/FCW — cybersecurity · score 3.75
A new plan emphasizes threat sharing and coordination ahead of the midterms, but does not explain how those commitments fit with proposed cuts to dedicated election security funding.
NORTHCOMPolicy & guidanceUnited States
2026-09-24 · GAO reports · score 4
What GAO Found Remote and isolated military installations are often away from population centers or located in austere environments, making the delivery of critical support services, such as health care or housing, challenging. GAO found that while remote and isolated installations consistently faced challenges in areas such as recruiting and retaining civilian personnel, the causes and severity of those challenges differed by location. For example, in Alaska, Eielson Air Force Base had the most vacant positions (428) while Fort Greely and Clear Space Force Station had no vacant critical support services positions. In 2024, the Department of Defense (DOD) issued guidance for designating installations as remote and isolated. As of May 2026, the Departments of the Army and Navy compiled lists of remote and isolated installations in accordance with this guidance. The Department of the Air Force has opted not to make a formal designation at this time. A DOD official stated that efforts to fully develop the risk assessment process outlined in the same guidance will begin once the initial designations of remote and isolated installations are complete. However, this guidance does not…
NORTHCOMSPACECOMPolicy & guidance
2026-09-24 · BBC News (World) · via TJFSCC Daily · score 4
Australia, which has strict social media restrictions and has proposed controls on algorithms and smart glasses, announced the breach at the UN.
PACOMBreach & leaked dataAustraliavia TJFSCC Daily
2026-09-24 · ABC News Australia · via TJFSCC Daily · score 4
An analysis of thousands of job advertisements posted by Cambodian scam syndicates reveals how the multi-billion-dollar industry has continued amid a crackdown by the country's government.
Scams & fraudSE Asia scam compoundsSE Asiavia TJFSCC Daily
2026-09-24 · The Hacker News · score 4.25
An active ClickFix campaign has been observed compromising legitimate Ukrainian business websites to inject bogus Cloudflare verification pages and trick victims into downloading a previously undocumented information stealer called Psychedelic. "When a visitor interacts with the page, the lure copies a Windows Installer command to the clipboard and instructs the visitor to paste it into the
EUCOMSocial engineeringMalware & toolingUkraine
2026-09-24 · The Hacker News · score 4.25
The logistics sector has become the target of a new malicious cyber campaign that distributes an Android spyware codenamed Corp MDM. According to Have I Been Squatted, the campaign uses fake Google Play pages branded as CEVA and TKW Logistics to distribute an Android Package Kit (APK) file that's dressed up as a system service. The delivered app has the package name "com.corp.mdm" Corp MDM
NORTHCOMMalware & toolingApps & devices
2026-09-24 · Department of Justice press releases · score 4.25
Four aliens, including 2 illegal aliens, have been charged with election-related crimes, announced United States Attorney David Metcalf.
NORTHCOMScams & fraudUnited States
2026-09-24 · Dark Reading · score 4.25
Agentic AI can smuggle arbitrary instructions from the Web, across multiple apps, into trusted internal communications channels.
Social engineeringCloud & identityAI & cyber
2026-09-24 · The Straits Times (Asia) · via TJFSCC Daily · score 4.25
New regulations may include mandatory reporting for AI companies if their products engage in security breaches
PACOMBreach & leaked dataAustraliavia TJFSCC Daily
2026-09-24 · DefenseScoop · score 5
Tightening security on the southern border has been a top Defense Department priority since the start of the second Trump administration.
NORTHCOMSPACECOMOPSEC & personal securityPolicy & guidanceUnited States
2026-09-24 · The Globe and Mail (World) · via TJFSCC Daily · score 5.25
Incident is one of several recent breaches by rogue AI agents
PACOMAI & cyberBreach & leaked dataAustraliavia TJFSCC Daily
2026-09-24 · Military Times · via TJFSCC Daily · score 5.5
Unauthorized users accessed files containing the personal information of U.S. military personnel, a new breach notification letter warns.
NORTHCOMBreach & leaked dataPolicy & guidanceUnited Statesvia TJFSCC Daily
2026-09-24 · Yonhap News (English) · via TJFSCC Daily · score 5.75
MEXICO CITY, Sept. 24 (Yonhap) -- South Korean President Lee Jae Myung on Thursd...
EUCOMPACOMBreach & leaked dataUkraineROKvia TJFSCC Daily
2026-09-24 · Yonhap News (English) · via TJFSCC Daily · score 5.75
MEXICO CITY/SEOUL, Sept. 24 (Yonhap) -- South Korean President Lee Jae Myung on ...
EUCOMPACOMBreach & leaked dataUkraineROKvia TJFSCC Daily
2026-09-24 · Yonhap News (English) · via TJFSCC Daily · score 5.75
MEXICO CITY/SEOUL, Sept. 24 (Yonhap) -- South Korean President Lee Jae Myung on ...
EUCOMPACOMBreach & leaked dataUkraineROKvia TJFSCC Daily
2026-09-24 · The Record (Recorded Future) · score 6.25
An OpenAI agent gained “unauthorized access” to “non-public files” from an Australian government health website in June, Prime Minister Anthony Albanese said.
PACOMBreach & leaked dataPolicy & guidanceAustralia
2026-09-24 · Nextgov/FCW — cybersecurity · score 6.5
Researchers discovered access to rail administration systems, a hospital alert channel and sensitive records in a new effort aimed at organizations with limited cyber resources.
EUCOMNORTHCOMBreach & leaked dataCritical infrastructureAI & cyberRussiaUkraine
2026-09-24 · Transformer · via AI feed · score 7
*Photo credit: Hilary Wardhaugh/Getty Images. Image: Oliver Kemp for Transformer* On Wednesday, Australian Prime Minister Anthony Albanese [revealed](https://www.pm.gov.au/media/press-conference-new-york) that an OpenAI agent gained “unauthorized access” to an Australian government website, accessing non-public information. It’s thought to be the first time an AI agent has autonomously hacked into a government system. After a summer of [AI incidents](https://www.transformernews.ai/p/rogue-ai-incidents-timeline), “AI agent autonomously hacked real-world website” is nothing new. But OpenAI’s…
PACOMNORTHCOMPolicy & guidanceAI & cyberAustraliavia AI feed
2026-09-24 · The Globe and Mail (World) · via TJFSCC Daily · score 7.25
Australia said on Wednesday an OpenAI agent breached a government health data portal in June, gaining unauthorized access to files, in what could be the first known instance of an AI agent hacking a government website.
PACOMBreach & leaked dataPolicy & guidanceAI & cyberAustraliavia TJFSCC Daily
2026-09-24 · The Register — security · score 8
Contact details and order records accessed, but PC maker is keeping schtum on how many customers are affected
NORTHCOMSPACECOMBreach & leaked dataRansomwareSocial engineering
2026-09-23 · ESET WeLiveSecurity · score 2.5
Crypto ATM scams often follow a predictable script – here’s how to recognize it and what to do if you’ve already been caught out
Scams & fraud
2026-09-23 · SecurityWeek · score 3
Hackers impersonated the company’s personnel and contacted its employees to gain access to Astrana Health’s servers.
Breach & leaked dataSocial engineering
2026-09-23 · SecurityWeek · score 3.25
The cybercrime platform leveraged AI at every step of the attack chain, including writing social engineering messages and deciding targets.
Social engineeringAI & cyber
2026-09-23 · Dark Reading · score 3.25
Threat actors are poisoning ChatGPT, Gemini, and Google AI Overview answers by seeding the Web with malicious links and data and then optimizing the content.
Social engineeringAI & cyber
2026-09-23 · Department of the Air Force · score 3.5
Top leaders of the Air Force and Space Force, joined by their spouses, offered observations into the lives of military families and how that dynamic contributes in real ways to readiness and defense of the nation.
SPACECOMOPSEC & personal security
2026-09-23 · U.S. Space Force · score 3.5
Top leaders of the Air Force and Space Force, joined by their spouses, offered observations into the lives of military families and how that dynamic contributes in real ways to readiness and defense of the nation.
SPACECOMOPSEC & personal security
2026-09-23 · BBC News (World) · via TJFSCC Daily · score 4.25
Albanese said he expressed "concern" to OpenAI founder Sam Altman, after authorities were informed three months after the breach in June.
PACOMBreach & leaked dataAustraliavia TJFSCC Daily
2026-09-23 · The Japan Times · via TJFSCC Daily · score 4.25
OpenAI took three months to alert the Australian government about the breach.
PACOMBreach & leaked dataAustraliavia TJFSCC Daily
2026-09-23 · Nikkei Asia · via TJFSCC Daily · score 4.25
PACOMBreach & leaked dataAustraliavia TJFSCC Daily
2026-09-23 · Department of Justice press releases · score 4.5
A federal jury in the District of Columbia convicted Devontee Parker, 38, of Dallas, today for sex trafficking by force, fraud, or coercion, interstate transportation for purpose of prostitution, and interstate travel in aid of racketeering.
NORTHCOMScams & fraudUnited States
2026-09-23 · SANS Internet Storm Center · score 4.5
Yesterday, we received a phishing email with an interesting link. At first sight, it looks like garbage, but every piece of it has been carefully crafted to confuse basic security controls. Here is the defanged link:
NORTHCOMVulns & exploitsSocial engineeringUnited States
2026-09-23 · NPR World · via TJFSCC Daily · score 4.5
Prime Minister Anthony Albanese said he was extremely concerned about OpenAI 's breach of an Australian health department website that the artificial intelligence company took too long to reveal.
PACOMBreach & leaked dataAustraliavia TJFSCC Daily
2026-09-23 · ABC News Australia · via TJFSCC Daily · score 4.75
Anthony Albanese couldn't have picked a better time to drop the metaphorical bomb that a rogue artificial intelligence agent breached an Australian government system.
PACOMBreach & leaked dataAustraliavia TJFSCC Daily
2026-09-23 · BleepingComputer · score 6.5
A new Android malware-as-a-service (MaaS) platform called RemControl is targeting users through malvertising campaigns that impersonate the TVTap IPTV application. [...]
EUCOMNORTHCOMMalware & toolingApps & devicesSocial engineeringCanada
2026-09-23 · South China Morning Post (China) · via TJFSCC Daily · score 6.75
Hours before Chinese President Xi Jinping arrived in the US for a high-stakes summit, US Secretary of State Marco Rubio moved to restrict visas for those who “engage in or facilitate” birth tourism, a practice the Trump administration has increasingly accused China of. “By restricting visa issuance of those who both engage in and profit from this fraud, we are sending a clear message: the United States will not allow foreigners to exploit our immigration system and violate the sanctity of US...
NORTHCOMPACOMScams & fraudChinaUnited Statesvia TJFSCC Daily
2026-09-23 · The Register — security · score 7.25
Regulator wants to know whether parent Aylo did its homework before reopening the door to UK iPhone users
EUCOMApps & devicesBreach & leaked dataOPSEC & personal securityUK
2026-09-23 · DefenseScoop · score 9.5
Senior defense officials provided an update on the department’s adoption of AI at DefenseTalks.
NORTHCOMSPACECOMAI & cyberOPSEC & personal securitySupply chainUnited States
2026-09-23 · Nextgov/FCW — cybersecurity · score 12
ShinyHunters claimed theft of FBI employee data and released a sample of about 5,000 entries with names, home addresses and family details. The FBI is investigating (Nextgov/FCW).
Personnel-record leaks put home addresses and families in criminal hands.
Consider reminding personnel to limit home and family details online.
NORTHCOMPACOMBreach & leaked dataOPSEC & personal securityShinyHuntersUnited StatesAI-curated
2026-09-22 · Dark Reading · score 3.25
Microsoft seized 50 websites and disabled more than 150 domains as part of a coordinated disruption effort against a phishing-as-a-service platform targeting Microsoft 365 accounts.
Social engineeringCloud & identity
2026-09-22 · BleepingComputer · score 3.5
Security researchers developed an attack that lets hackers with privileged access register a rogue external MFA provider that steals users' passwords during legitimate login attempts. [...]
OPSEC & personal securityCloud & identity
2026-09-22 · The Hacker News · score 3.5
Microsoft on Tuesday announced the takedown of the EvilTokens device code phishing service that it said used artificial intelligence (AI) "at every step of the attack chain." The action, carried out with authorization from the U.S. District Court for the Eastern District of Virginia, involved the efforts of Health-ISAC, alongside Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver
NORTHCOMSocial engineeringUnited States
2026-09-22 · The Hacker News · score 4
A critical vulnerability in Bifrost, an open-source AI gateway that routes requests to more than 20 LLM providers, allows an unauthenticated attacker to run arbitrary commands on the gateway server with a single HTTP request. The flaw, tracked as CVE-2026-90898 (CVSS score: 9.8), affects all versions of the Bifrost HTTP transport before 2.1.0 when management authentication is
Vulns & exploitsSupply chainAI & cyber
2026-09-22 · Department of Justice press releases · score 4.25
Olamide Shanu, 35, a Nigerian national, pleaded guilty yesterday in the District of Idaho to charges related to his role in several cyber-enabled schemes that defrauded approximately 150 American victims and caused millions of dollars in losses. Shanu made more than $2,500,000 from these fraud schemes.
NORTHCOMScams & fraudUnited States
2026-09-22 · Department of Justice press releases · score 4.5
A federal jury in the Northern District of Indiana convicted Anthony Mayers, 36, of Gary, Indiana, of four counts of trafficking by force, fraud, or coercion and other related charges.
NORTHCOMScams & fraudUnited States
2026-09-22 · The Japan Times · via TJFSCC Daily · score 5
Details of the email exchange were outlined by Mizuho as part of a lawsuit in Singapore, where it has accused Radiant World of an alleged fraud.
PACOMScams & fraudSE Asiavia TJFSCC Daily
2026-09-22 · The Record (Recorded Future) · score 6.25
Available on Telegram for a $1,500 initiation fee and a recurring monthly $500 subscription, EvilTokens provided cybercriminals with artificial intelligence tools enabling them to compromise accounts, analyze breached inboxes and find the best methods for monetizing their access through fraud.
EUCOMBreach & leaked dataScams & fraudApps & devicesUK
2026-09-22 · ABC News Australia · via TJFSCC Daily · score 6.25
Police say they have found dozens of people from Indonesia allegedly being held against their will in Papua New Guinea and forced to carry out online scams.
PACOMScams & fraudPacific IslandsSE Asiavia TJFSCC Daily
2026-09-22 · CyberScoop · score 9.25
The popular phishing-as-a-service platform used AI throughout the attack chain, allowing cybercriminals to steal tokens for account takeover and business email compromise.
NORTHCOMPACOMScams & fraudSocial engineeringUnited StatesUK
2026-09-22 · The Register — security · score 9.25
Microsoft seized 50 EvilTokens sites and UK police arrested two suspected admins. The device-code phishing kit bypassed MFA to compromise 12,000+ inboxes (The Register).
Device-code phishing defeats MFA because the victim approves the sign-in.
Be aware: never enter a device code you did not request.
EUCOMNORTHCOMSocial engineeringCloud & identityUKUnited StatesAI-curated
2026-09-21 · SecurityWeek · score 2.5
The cybersecurity firm believes the data breach was the result of the May 2026 TanStack supply chain attack.
Supply chainBreach & leaked data
2026-09-21 · The Record (Recorded Future) · score 2.75
Ireland’s Data Protection Commission will fine Google more than €403 million ($462 million) over the tech giant’s processing of location data, concluding an inquiry into the company that began in early 2020.
EUCOMOPSEC & personal security
2026-09-21 · The Hacker News · score 2.75
Google has been fined €403 million for breaking the EU's data protection law, the GDPR, in the way three of its features handled people's location data from May 2018 to February 2020. Ireland's Data Protection Commission (DPC), Google's lead regulator in the EU, also ordered the company to make its processing comply with the law within 6 months. The DPC has not said publicly which
EUCOMOPSEC & personal security
2026-09-21 · SecurityWeek · score 3
The attackers impersonate at least 40 companies and disable 145 security products to deploy infostealer malware.
Malware & toolingSocial engineering
2026-09-21 · BleepingComputer · score 3
Ecommerce platform BigCommerce has alerted multiple merchants to data breaches after attackers compromised credentials for third-party Ribon applications and used them to inject malicious scripts into online stores. [...]
NORTHCOMBreach & leaked dataSupply chain
2026-09-21 · Palo Alto Unit 42 · score 3.25
We explore how AWS neutralizes exposed IAM credentials using managed policies, detailing GitHub secret scanning and CloudTrail monitoring strategies.
NORTHCOMBreach & leaked dataCloud & identity
2026-09-21 · Have I Been Pwned — breaches · score 3.25
In 2019, the now-defunct B2B marketing leads database service LimeLeads suffered a data breach due to an exposed, unsecured Elasticsearch server. The incident exposed tens of millions of records of largely corporate contact data containing 17.8M unique email addresses, along with phone numbers, employers, job titles and geographic locations including state, city and postcode. Data: Email addresses, Employers, Geographic locations, Job titles, Phone numbers.
Breach & leaked data
2026-09-21 · SecurityWeek · score 3.75
The malware relies on AI for real-time device navigation and control, increasing adaptability and evasion.
NORTHCOMMalware & toolingApps & devices
2026-09-21 · SecurityWeek · score 3.75
Google has been fined 403 million euros ($463 million) for breaching the European Union’s strict privacy rules because it mishandled users’ location data.
EUCOMBreach & leaked dataOPSEC & personal security
2026-09-21 · Department of Justice press releases · score 5
Tomás Niembro Concha, 64, a Spanish and Venezuelan national, the former chief executive officer of Nodus International Bank (Nodus Bank), a Puerto Rican international bank, was sentenced to 112 months in prison and three years of supervised release. Niembro led a scheme to fraudulently obtain at least $24.9 million from Nodus Bank and conspired to evade U.S. sanctions against Venezuela. Niembro was ordered to forfeit over $16.9 million, which represents the value of the proceeds he derived from the wire fraud conspiracy.
SOUTHCOMNORTHCOMScams & fraudUnited States
2026-09-21 · BleepingComputer · score 5.25
Microsoft has reminded admins to migrate Entra ID users to phishing-resistant authentication methods to avoid sign-in disruptions after it retires SMS first-factor sign-in starting in February 2027. [...]
Cloud & identityOPSEC & personal securitySocial engineering
2026-09-21 · The Hacker News · score 5.5
The threat actor known as SideCopy has been observed using spear-phishing lures to target academic institutions in India, expanding their strategic focus beyond government entities. "SideCopy campaign operations typically initiate through spear-phishing campaigns that leverage the abuse of mshta.exe to execute malicious scripts and circumvent standard security protocols," Trellix researchers
PACOMNORTHCOMSocial engineeringIndia
2026-09-21 · The Diplomat · via TJFSCC Daily · score 5.75
A conversation with award-winning Filipina journalist Eunice Barbara Novio.
PACOMScams & fraudPhilippinesSE Asiavia TJFSCC Daily
2026-09-21 · Have I Been Pwned — breaches · score 7
In October 2024, news of a data breach exposing Burger King Russia customers broke following an August attack on the Mindbox marketing automation platform. The breach exposed 3.2M unique email addresses along with names, genders, dates of birth, phone numbers and approximate geolocations, with the data spanning 2018 to August 2024. Burger King Russia acknowledged the incident and advised it did not include payment or passport details. Data: Dates of birth, Email addresses, Genders, Geographic locations, Names, Phone numbers.
EUCOMBreach & leaked dataOPSEC & personal securityRussia
2026-09-21 · The Register — security · score 11
Attackers are courting crate owners with plausible company profiles and booby-trapped recruitment calls
PACOMEUCOMMalware & toolingSocial engineeringSupply chainNorth KoreaJapan
2026-09-19 · BleepingComputer · score 2.5
BragJack, a proof-of-concept attack from Forever Security's Gal Weizman, hijacks the AI assistants in Chrome, Edge, Opera Neon, Perplexity Comet, and Claude in Chrome using one malicious extension. The Prompt Forcing technique earned over $20,000 in bounties and two CVEs. [...]
NORTHCOMVulns & exploits
2026-09-19 · The Hacker News · score 5.5
Identity visibility is a starting point for modern identity security, because stolen and misused credentials are among the most frequently reported initial access vectors in breach research, including Verizon's annual Data Breach Investigations Report. This article explains what identity visibility means in IAM, why cloud and multicloud environments complicate it, which capabilities matter in
Cloud & identityBreach & leaked dataTelecom & cables
2026-09-18 · Dark Reading · score 3.5
MFA is essential, but it cannot replace OAuth governance, least-privilege scopes, consent monitoring, and rapid revocation.
OPSEC & personal securityCloud & identity
2026-09-18 · BleepingComputer · score 3.75
An ongoing malware campaign uses SEO-optimized GitHub repositories to impersonate well-known software firms to push a previously undocumented information stealer called Rapuncel. [...]
NORTHCOMMalware & toolingSocial engineering
2026-09-18 · Palo Alto Unit 42 · score 4
Analysis of how default configurations in AWS AgentCore Harness allow prompt injection to exfiltrate credentials, and key steps to secure your agents.
Cloud & identityAI & cyber
2026-09-18 · Department of Justice press releases · score 4.5
Today, the Justice Department announced charges against 16 individuals in connection with illegal voting, illegal voter registration, and related election-fraud schemes across the country. The charges include unlawful voting by non-citizens in federal elections, false claims of citizenship to register or vote, and related offenses including wire fraud, naturalization fraud, passport fraud, and unlawful firearm purchases uncovered during the course of these investigations.
NORTHCOMScams & fraudUnited States
2026-09-18 · Department of Justice press releases · score 6.25
Today, the Department of Justice announced revisions to the Justice Manual to strengthen its fight against fraud under the False Claims Act through clearer standards that promote fair and effective enforcement. These revisions clarify the limits on the use of sub-regulatory guidance across Department litigation and when the Department will seek dismissal of qui tam actions that do not serve the interests of the United States.
NORTHCOMScams & fraudPolicy & guidanceUnited States
2026-09-18 · DefenseScoop · score 6.75
AAFES is investigating suspicious messages sent to military customers via its official email and the My Exchange app, including a fake 'AAFES Security Team' wish-list link. It has not said whether a breach occurred.
It came through a channel Guardians and families are trained to trust; AAFES serves ~30M shoppers.
Recommend telling families to delete the message and verify by calling AAFES support.
NORTHCOMPACOMScams & fraudSocial engineeringUnited StatesAI-curated
2026-09-18 · The Register — security · score 6.75
FBI IC3 reports law-enforcement and government impersonation scams have cost victims over $1.6B across ~61,000 complaints since January 2025, averaging more than $26,000 each.
Rank, unit, and duty status are easy to research, and a fake police caller carries extra weight.
Be aware no agency or court demands payment by phone, gift card, wire, or crypto.
NORTHCOMScams & fraudUnited StatesAI-curated
2026-09-18 · CyberScoop · score 7.75
Ahmed Elbadawy pocketed massive proceeds from his crimes. Prosecutors are seeking the forfeiture of about $17.6 million in virtual currency, luxury vehicles, and a vast collection of jewelry and designer bags.
NORTHCOMScams & fraudCloud & identityRansomwareScattered SpiderUnited States
2026-09-18 · The Register — security · score 14.5
WaterPlum recruiters used bogus coding tests to backdoor jobseekers and raid more than 7,000 crypto wallets
PACOMEUCOMMalware & toolingSocial engineeringDPRK & crypto theftDPRK IT workersWaterPlumNorth KoreaROK
2026-09-17 · Dark Reading · score 2.5
AI-driven cyberattacks used to be exotic. Soon, it'll be odd if threat actors aren't using agents to do all of their bidding.
NORTHCOMBreach & leaked dataAI & cyber
2026-09-17 · Department of Justice press releases · score 3.5
The Department of Justice announced today that it is transferring $29.7 million to Curaçao in three installments.
Scams & fraud
2026-09-17 · Google Security Blog · score 3.75
New Android libraries give enterprises and OEMs a clear, unified view of a device's security status across all system components.
Vulns & exploitsApps & devices
2026-09-17 · Department of Justice press releases · score 4.25
Samir Ousman Alsheikh, 74, a former Syrian prison warden and provincial governor, was sentenced today to 60 years in prison for torturing prisoners and lying to U.S. immigration officials to gain entry to the United States.
NORTHCOMScams & fraudUnited States
2026-09-17 · BleepingComputer · score 4.75
A new Android malware called RatHat has been discovered, targeting users with an AI-powered subsystem that helps operators remotely navigate compromised devices. [...]
NORTHCOMMalware & toolingApps & devicesAI & cyber
2026-09-17 · BleepingComputer · score 4.75
Brevo confirmed that attackers stole a Cloudflare API key and used it to inject malicious ClickFix scripts into its websites and JavaScript files embedded on customer sites to distribute malware. [...]
NORTHCOMSupply chainSocial engineeringMalware & tooling
2026-09-17 · FBI IC3 Public Service Announcements · score 5
Social engineeringScams & fraud
2026-09-17 · Department of Justice press releases · score 5.75
A Phoenix woman was sentenced to 14 years in prison in connection with her role in fraudulently billing Arizona’s Medicaid agency more than $69 million in less than one year for addiction treatment therapy. Many of the patients the defendant used to fuel her scheme were Native Americans covered by Arizona Medicaid under a specific program that reimbursed at higher rates than other Medicaid programs. In addition to the prison sentence, the defendant was ordered to pay almost $55 million in restitution, and to forfeit almost $9.5 million in fraud proceeds seized from seven bank accounts she controlled and almost $7 million in real estate properties.
NORTHCOMScams & fraudMalware & toolingUnited States
2026-09-17 · The Hacker News · score 6
The Iran-linked "hacktivist" persona known as Handala Hack has been attributed to a Telegram-based surveillance backdoor called HEAVYGRAM and a Delphi-based utility known as CRUDEEXCLUDE. "HEAVYGRAM offers builtin commands supporting remote command execution, system, network and process information discovery, data and Telegram session files exfiltration, screenshot capture, DLL sideloading,
CENTCOMApps & devicesMalware & toolingCritical infrastructureIran
2026-09-17 · Microsoft Security / MSTIC · score 6
The latest email security benchmarking reports show strong Microsoft Defender performance across pre-delivery and post-delivery scenarios and reveal where threats and defenses continue to evolve.
NORTHCOMSocial engineeringBreach & leaked dataSupply chain
2026-09-17 · Department of the Air Force · score 6
Lt. Gen. Daniel Tulley, commander of Air Mobility Command, joined fellow commanders and senior leaders to address service members, defense industry partners and journalists during the 2026 AFA Air, Space and Cyber Conference.
OPSEC & personal security
2026-09-17 · The Japan Times · via TJFSCC Daily · score 6.25
According to local media, authorities seized what appeared to be counterfeit Japanese police identification booklets.
PACOMScams & fraudSupply chainJapanvia TJFSCC Daily
2026-09-17 · Infosecurity Magazine · score 7
Researchers at Zimperium have uncovered a new Android malware strain, dubbed RatHat, with spyware and backdoor capabilities
PACOMMalware & toolingApps & devicesChina
2026-09-17 · The Register — security · score 7.25
Think tank points out that companies banned by Washington will help run the regime that Uncle Sam now controls
PACOMSOUTHCOMAI & cyberBreach & leaked dataAPT & espionageChinaUnited States
2026-09-17 · The Register — security · score 7.5
Platforms comply just enough to avoid being blocked, leaving the regulator chasing debt
EUCOMNORTHCOMOPSEC & personal securityBreach & leaked dataTelecom & cablesUK
2026-09-17 · The Hacker News · score 8.75
Cybersecurity researchers have flagged a new Android malware called RatHat that's assessed to be operated by China-based threat actors and features an artificial intelligence (AI)-powered system to navigate and control compromised devices. "Distributed primarily via targeted smishing (SMS/text phishing) and malvertising campaigns leading to deceptive third-party download portals, RatHat uses
PACOMNORTHCOMMalware & toolingSocial engineeringApps & devicesChina
2026-09-16 · The Record (Recorded Future) · via TJFSCC Daily · score 4.5
Ukraine’s parliament has approved tougher criminal penalties for involvement in fraudulent call centers and the theft of personal data, following a corruption scandal in which prosecutors were accused of taking bribes to protect scam operations.
EUCOMScams & fraudBreach & leaked dataUkrainevia TJFSCC Daily
2026-09-16 · The Record (Recorded Future) · via TJFSCC Daily · score 4.5
The Guarding Unprotected Aging Retirees from Deception Act (GUARD) attempts to address a common complaint from the victims of online scams like pig butchering — that such cases typically do not rise to the level of a federal investigation but local law enforcement is unequipped to properly investigate them.
NORTHCOMScams & fraudSE Asia scam compoundsUnited Statesvia TJFSCC Daily
2026-09-16 · Department of Justice press releases · score 4.75
Law enforcement today arrested two defendants out of three total charged in separate federal homelessness corruption and fraud cases, including a founder of a Culver City-based nonprofit who allegedly misappropriated more than $7.5 million in taxpayer funds, and used this money for commercial real estate and to finance the construction of a nightclub and adjacent bingo hall.
NORTHCOMScams & fraudUnited States
2026-09-16 · The Hacker News · score 5.25
N0va is targeting organizations across North America and Europe with phishing campaigns that impersonate trusted services and abuse legitimate authentication flows. Successful attacks can give threat actors access to valid accounts without relying on obvious malware activity. From there, a single compromised identity can open the door to sensitive data, business systems, and additional cloud
EUCOMNORTHCOMSocial engineeringCloud & identityMalware & tooling
2026-09-16 · Department of Justice press releases · score 5.75
Dmitry Shushlebin, 45, a Russian citizen living in Miami Beach, Florida, was sentenced to six years in prison and three years of supervised release for organizing an identity theft fraud scheme that included efforts by the conspirators to submit fraudulent voter registrations.
EUCOMNORTHCOMScams & fraudCloud & identityRussia
2026-09-16 · Department of the Air Force · via Space Watch · score 6
AMC's deputy commander joined military and defense industry leaders to address service members, partners and journalists on the evolving demands of long-range airpower during the 2026 AFA Air, Space and Cyber Conference.
OPSEC & personal securityvia Space Watch
2026-09-16 · Krebs on Security · score 6.5
The consumer data broker Radaris.com has long had a reputation for ignoring requests to remove personal information from its vast empire of people-search services online. That reputation caught up with the company recently in a lawsuit alleging Radaris violated a New Jersey privacy law that provides for hefty fines against data brokers that publish personal information on state law enforcement officials. In the face of repeated stonewalling and prevarication by attorneys for Radaris, the judge in the case ordered that radaris.com and more than a dozen other data broker domains be transferred to the plaintiffs.
EUCOMNORTHCOMOPSEC & personal securityRansomwareUkraineRussia
2026-09-16 · SentinelLabs · score 11
Two Hugging Face accounts reveal that OpenAI's agents staged relay code, internal probes and ChatGPT account registration beyond the published timeline.
PACOMNORTHCOMCloud & identitySpace & SATCOMAI & cyberChina
2026-09-16 · The Register — security · score 11.75
Google disclosed CVE-2026-58704, an improper authorization flaw in Pixel cellular modems exploitable with no user interaction, and warned of limited targeted exploitation. CISA added it to KEV the next day.
A personal-device risk needing no user mistake; targeted spyware follows people, not networks.
Recommend Pixel users apply the September update; careful browsing does not mitigate zero-click.
GLOBALmobile_devicevulnerability_exploitationspywareUnited StatesAI-curated
2026-09-15 · U.S. Space Force · score 4.5
The U.S. Space Force will open its FY27 Interservice Transfer application window Sept. 15 through Oct. 2, 2026, seeking experienced active-duty service members from across the joint force, particularly those with space-related expertise.
SPACECOMNORTHCOMOPSEC & personal securityUnited States
2026-09-15 · Department of Justice press releases · score 4.75
Alex Nain Saab Moran, 54, of Caracas, Venezuela, and formerly of Baranquilla, Colombia, a former Minister of Industry in the regime of former Venezuelan President Nicolás Maduro, pleaded guilty today to conspiring to launder proceeds of a massive bribery and fraud scheme in Venezuela and the United States.
SOUTHCOMNORTHCOMScams & fraudUnited States
2026-09-15 · Department of Justice press releases · score 4.75
A federal grand jury in the Eastern District of Michigan returned an indictment charging Emory Matthews, 62, of Farmington Hills, Michigan, with conspiring to bill Medicare for psychotherapy services that were never provided to patients of an adult day care center owned by his wife. He was arrested yesterday.
NORTHCOMScams & fraudUnited States
2026-09-15 · UK NCSC · score 5
UK and allies provide advice to help organisations and individuals at risk detect and counter the threat from CHOSEN BRICK malware.
CENTCOMEUCOMMalware & toolingIranUK
2026-09-15 · The Japan Times · via TJFSCC Daily · score 5.5
While the number of cases has risen just 4.1% from the same period last year, data shows the amount of money involved is up 19.8%.
PACOMScams & fraudROKvia TJFSCC Daily
2026-09-15 · The Hacker News · score 7.25
Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and
EUCOMNORTHCOMMalware & toolingSocial engineeringApps & devicesRussia
2026-09-14 · FTC Consumer Alerts · score 4.75
The FTC is hearing about a scam targeting some of the hardest working people out there: farmers. Scammers posing as farm equipment businesses are selling (fake) equipment to farmers, who end up empty-handed. Here’s how the scam works and how to avoid it.
Social engineeringScams & fraud
2026-09-14 · Recorded Future — Insikt · score 9.75
Analyze Tajin Group's role in phishing and Chinese money laundering. Discover how this Telegram-based vendor exploits payment gateways and adapts its financial fraud operations.
PACOMCENTCOMSupply chainSocial engineeringScams & fraudChina
2026-09-13 · Have I Been Pwned — breaches · score 3
In August 2026, millions of records allegedly sourced from Chess.com were posted online . The data contained 7.3M rows with 4.6M unique email addresses, along with usernames, names, countries and data relating to users' Chess.com accounts. Analysis of the data suggested it had been obtained by scraping. When loaded into HIBP, 99% of the email addresses had already appeared in previous data breaches, further supporting the scraping theory. Read more about scrapes and data breaches. Data: Email addresses, Geographic locations, Names, Usernames.
Breach & leaked data
2026-09-13 · The Register — security · score 6.75
Passkeys promise fewer phishing headaches – and £600 a day off Whitehall's SMS bill
EUCOMNORTHCOMOPSEC & personal securitySocial engineeringCloud & identityUK
2026-09-11 · Rapid7 blog · score 3.5
Introduction The surge in emerging threat actors directly correlates with the rapid escalation of victim counts and stolen financial resources. Simultaneously, this growth has spurred the proliferation of specialized supply storefronts across social media platforms, dark web channels, and various smaller niche marketplaces. Security teams today face evolving challenges, requiring them to continuously refine monitoring channels, adjust operational strategies, and foster cross-functional internal collaboration to capture actionable intelligence. With fraud damages anticipated to approach hundreds of billions of USD , security teams must navigate numerous non-compliant channels while ingesting and processing diverse data formats—such as documents, imagery, video, and unformatted text—linked to organizational assets. The recent introduction of a new Fraud framework by the MITRE organization underscores the critical need to combat fraud and highlights the significant danger these threat actors pose to all organizations. The MITRE organization has been taking a positive step towards standardizing the fight against fraud, while helping organizations target the relevant directions to…
Scams & fraudStandards & compliance
2026-09-11 · South China Morning Post (China) · via TJFSCC Daily · score 7
A young Malagasy woman was stopped at Madagascar’s Ivato International Airport last month as she prepared to travel to China for a proposed marriage, according to local media reports citing police. She had reportedly been promised 10 million ariary (US$2,300) once she arrived and married a Chinese man. The case led police to investigate a suspected network involved in arranging similar marriages. Four people were detained, and police reportedly recovered false stamps, documents and 10 Malagasy...
PACOMAFRICOMScams & fraudChinavia TJFSCC Daily
2026-09-10 · Microsoft Security / MSTIC · score 6.25
Microsoft examines an AI-assisted business email compromise campaign that used executive impersonation and fake invoices to target finance teams with ACH payment fraud.
NORTHCOMSocial engineeringScams & fraudAI & cyberUnited States
2026-09-09 · FTC Consumer Alerts · score 3.25
Recent violent storms, tornadoes, wildfires, heat waves, and extreme flooding are a reminder that severe weather and natural disasters can happen anytime, anywhere, and with little warning. September is National Preparedness Month and it’s a great time to plan for whatever may come your way.
Scams & fraud
2026-09-09 · Palo Alto Unit 42 · score 3.75
An investigation into how cybercriminals used YouTube gaming lures and SEO poisoning to deliver multi-payload malware to enterprise networks.
NORTHCOMMalware & toolingSocial engineering
2026-09-09 · Infosecurity Magazine · score 5.75
Gigabud clones banking apps into a work profile to break the link between malware alerts and fraud
NORTHCOMScams & fraudApps & devicesMalware & tooling
2026-09-09 · Microsoft Security / MSTIC · score 6
Passkey-themed social engineering is being used to compromise identities and enable broader cloud attacks. Learn how threat actors establish MFA persistence, abuse Microsoft Graph for reconnaissance, and access SharePoint, OneDrive, and email data, along with key detection and mitigation guidance.
NORTHCOMCloud & identitySocial engineeringOPSEC & personal security
2026-09-09 · Nextgov/FCW — cybersecurity · score 6
The “hack-for-hire” entities have systematically targeted newsrooms covering corporate fraud, legal teams in high-stakes litigation and NGOs.
NORTHCOMPACOMScams & fraudIndiaUnited States
2026-09-09 · Microsoft Security / MSTIC · score 6.5
Microsoft introduces the Cloud Web Applications Threat Matrix, a MITRE ATT&CK-aligned framework that helps defenders understand, prioritize, and mitigate threats to cloud-hosted web apps and serverless platforms.
NORTHCOMCloud & identityBreach & leaked dataPolicy & guidance
2026-09-09 · Infosecurity Magazine · score 6.5
The US Treasury has placed sanctions on notorious Chinese cybercrime marketplace Xinbi Guarantee
PACOMNORTHCOMScams & fraudChina
2026-09-09 · Have I Been Pwned — breaches · score 7.5
In August 2026, healthcare and pharmaceutical company McKesson was targeted in a ShinyHunters "pay or leak" extortion campaign . The group subsequently published a substantial corpus of data they alleged was sourced from the company, which included 6.4M unique email addresses among other personal and corporate data attributes. The impacted data related to a range of individuals and roles, including marketing campaign recipients, patients, staff and healthcare provider contacts. In McKesson's disclosure notice , the company advised it had identified unauthorised access to "certain third-party applications and the exfiltration of certain data was associated with a subset of customers within our Oncology & Multispecialty and Medical-Surgical business units", but had "reasonable assurance of no ongoing unauthorized activity". Data: Dates of birth, Email addresses, Employers, Genders, Names, Personal health data, Phone numbers, Physical addresses.
Breach & leaked dataSupply chainRansomwareShinyHunters
2026-09-08 · The Register — security · score 6
Medical device giant warns August intrusion will hit Q3 and full-year sales and earnings as recovery drags on
NORTHCOMBreach & leaked dataPolicy & guidanceRansomware
2026-09-08 · Dark Reading · score 6.25
A Chinese-language group is compromising government and education sites to create a reverse-proxy network with gambling-themed sites.
SOUTHCOMPACOMSocial engineeringChina
2026-09-08 · The Register — security · score 8.25
Researchers got inside the crooks' admin panel and found 5,137 stolen records tied to 461 organizations
PACOMNORTHCOMCloud & identitySocial engineeringOPSEC & personal securityIndia
2026-09-08 · Cisco Talos · score 9
We assess with moderate confidence that the attacks are not targeted at a particular organization, but are a part of a cryptocurrency and credentials-stealing operation using the Amatera stealer as the primary payload.
EUCOMNORTHCOMMalware & toolingSocial engineeringPolicy & guidanceRussiaUkraine
2026-09-06 · The Diplomat · via TJFSCC Daily · score 5.25
In poor areas such as Jamtara and Mewat, cyber scams have become an important source of household income.
PACOMNORTHCOMScams & fraudIndiavia TJFSCC Daily

Space & Cyber Professionals 0 items Context for the cyber and space workforce: strategy, doctrine, policy, organization, workforce, standards, exercises, industry and technology trends.

2026-10-06 · GAO reports · score 3.75
What GAO Found Quantum computers leverage qubits (the quantum equivalent of classical computer bits) to solve specific problems significantly faster than classical computers. However, the emergence of quantum computers could undermine the cryptography (e.g., encryption) that federal agencies use to secure their systems. Today’s quantum computers cannot yet break this cryptography. But a future quantum computer of sufficient size and sophistication—referred to as a cryptographically relevant quantum computer (CRQC)—could potentially do so for certain cryptography. Most industry experts believe that a CRQC will be developed, possibly as soon as the 2030s. However, development estimates vary widely due to several factors, such as uncertainty in the rate of growth for qubits and how many qubits will be needed. Once a CRQC is developed, its use could have devastating impacts to federal systems reliant on vulnerable cryptography. For example, a malicious actor could use a CRQC tocompromise systems that ensure the authenticity of system users—thus allowing the actor to gain access to sensitive information; and decrypt (or unlock and view) data that the actor acquires and stores prior to…
NORTHCOMStandards & complianceUnited States
2026-10-06 · Inside Defense · via TJFSCC Daily · score 4.25
Stakeholders running the accreditation body behind the Pentagon's Cybersecurity Maturity Model Certification program have identified potential changes to the high-profile initiative, as industry awaits the results from a Defense Department review. “We believe strongly in the need for third-party certification,” Cyber AB CEO Matthew Travis said in a recent town hall , but he noted that where consultant firms are helping defense contractors implement CMMC “is what we’re waiting to see” from DOD. Travis said, “I could see a world where you know whether it's really the basics mapped to it,” where there are 20 or 40 controls that need to be tested by a certified third-party assessment organization and “the rest” could be a self-attestation. Travis said, “I could see a hybrid model.” Travis reflected on potential changes at a Sept. 29 town hall hosted by the Cyber AB in a conversation with the Cyber Engagement Forum executive director Mike Snyder. The Cyber EF is a spinoff of the Cyber AB focused on working with the practitioner community. DOD announced on July 13 a pause on implementing CMMC phase two , which was set to begin on Nov. 10 and would have added in a third-party assessment…
Supply chainStandards & complianceUnited Statesvia TJFSCC Daily
2026-10-05 · SecurityWeek · score 2.75
More than 730 cyber breaches affected over 270 million Americans last year, costing an average of $10 million per breach.
NORTHCOMBreach & leaked dataUnited States
2026-10-05 · The Record (Recorded Future) · score 3
Saif ‌al-Din Khader is cooperating with the FBI, reports said, as the bureau responds to a massive breach that exposed employee data.
NORTHCOMBreach & leaked dataShinyHuntersUnited States
2026-10-05 · Yonhap News (English) · via TJFSCC Daily · score 4
SEOUL, Oct. 6 (Yonhap) -- Police have launched an investigation into a recent se...
SPACECOMPACOMROKvia TJFSCC Daily
2026-10-05 · South China Morning Post (China) · via TJFSCC Daily · score 4
The United States has accused mainland China of hiring an American citizen of Chinese origin to surveil the family of Taiwanese leader William Lai Ching-te, days after President Xi Jinping’s state visit to Washington. The Federal Bureau of Investigation on Sunday arrested 34-year-old Zhang Wanying at Los Angeles International Airport, alleging that she attempted to flee the country and charged her with acting as an unregistered agent for the Chinese government. The FBI accused her of surveilling...
PACOMNORTHCOMUnited StatesChinavia TJFSCC Daily
2026-10-05 · The Straits Times (Asia) · via TJFSCC Daily · score 4
Police have launched a full-scale investigation into the hacking attacks against commercial banks.
PACOMNORTHCOMROKvia TJFSCC Daily
2026-10-05 · ExecutiveGov · via TJFSCC Daily · score 4.5
GAO has urged OMB to update IoT and OT device cybersecurity guidance as agencies work to finish device inventories. The post GAO Urges OMB to Update Cybersecurity Guidance for Agencies’ Networked Devices first appeared on Executive Gov .
Policy & guidanceApps & devicesvia TJFSCC Daily
2026-10-05 · The Globe and Mail (World) · via TJFSCC Daily · score 4.75
Case comes at fraught moment for bilateral relations, with Taiwan persistently at centre of military and diplomatic rivalry
PACOMNORTHCOMChinaTaiwanvia TJFSCC Daily
2026-10-05 · Industrial Cyber · via TJFSCC Daily · score 5
The U.S. Department of Energy’s (DOE) Office of Cybersecurity, Energy Security, and Emergency Response (CESER) today announced plans...
NORTHCOMSPACECOMCritical infrastructureUnited Statesvia TJFSCC Daily
2026-10-05 · The Japan Times · via TJFSCC Daily · score 5
In light of the influx of recent cyberattacks across Japan, here's what users can do to limit their own vulnerabilities.
PACOMVulns & exploitsJapanvia TJFSCC Daily
2026-10-05 · The Guardian (World) · via TJFSCC Daily · score 6
Unions, employer groups, banks and industry experts will appear at the four-day hearings along with OpenAI, Anthropic, Microsoft and Google Get our new political email , free app or daily news podcast OpenAI must explain how they will stop their models from inappropriately accessing Australian data, the Labor chair of the parliament’s committee on artificial intelligence has warned, ahead of federal inquiry hearings which will grill the tech company alongside Anthropic, Microsoft and Google. Independent senator David Pocock is also demanding answers, saying OpenAI “still have a lot they need to answer” about their AI agent accessing Services Australia data on Medicare and the company’s “appalling” tardiness in notifying the federal government about the incident. Follow our Australia politics live blog for latest updates
PACOMNORTHCOMAI & cyberAustraliaUnited Statesvia TJFSCC Daily
2026-10-05 · Industrial Cyber · score 6.5
Digitization of the marine transportation system has brought deep weaknesses, especially where Terminal Operating Systems (ToS) are involved....
NORTHCOMSupply chainVulns & exploitsMalware & toolingUnited States
2026-10-05 · Malwarebytes Labs · score 6.75
Two sets of US lawmakers introduced bills in late September and early October to tackle the growing concerns about automated license plate readers.
NORTHCOMStandards & complianceOPSEC & personal securityPolicy & guidanceUnited States
2026-10-04 · SecurityWeek · score 3.5
Known as Rey, the suspect is reportedly helping the FBI identify and locate other members of the extortion group.
NORTHCOMRansomwareShinyHuntersUnited States
2026-10-04 · The Guardian (World) · via TJFSCC Daily · score 4
The FBI ⁠arrested Wanying Zhang, also known as Heather, at Los Angeles International Airport before she left for China, the agency said US authorities arrested a California ⁠woman on ​Sunday, accusing her of spying on the son of Taiwan’s president at the behest of Chinese officials, the FBI said. The FBI ⁠arrested Wanying Zhang, also known as Heather, at Los Angeles International Airport on Sunday before her planned departure to China, the agency said in a ⁠statement. Authorities charged Zhang, 34, of Irvine, California, with acting as an unregistered foreign agent.
PACOMNORTHCOMChinaTaiwanvia TJFSCC Daily
2026-10-04 · Industrial Cyber · score 5
CyberSafe Foundation and SANS Institute have launched an AI security fellowship for women in cybersecurity across Africa. The...
AFRICOMSPACECOMAI & cyber
2026-10-04 · Inside Defense · via TJFSCC Daily · score 5.5
President Trump has announced that Director of National Intelligence Jay Clayton and Federal Trade Commission Chair Andrew Ferguson, along with senior Defense and personnel officials, will lead the Super Intelligence Force as a federal policy coordinating body and report back with proposed actions. Trump’s Oct. 4 “SI Force” statement underlines issues such as critical infrastructure security as well as consumer protections and singles out the FTC, the Pentagon and the Office of Personnel Management as leading players in crafting policy in the coming months. “I am announcing the formation of the Super Intelligence Force (SIF). The Super Intelligence Force is tasked with coordinating the effort of the Federal Government to ensure that America continues to lead the World in Super Intelligence, which many say is bigger than the Industrial Revolution, and the Internet, and will protect the interests, and improve the lives, of all Americans,” according to an Oct. 4 X post by the White House. The unreleased charter for the task force says it will report to Trump and White House Chief of Staff Susie Wiles within 120 days, according to reports . Trump earlier Sunday spelled out more…
NORTHCOMCritical infrastructureScattered SpiderUnited Statesvia TJFSCC Daily
2026-10-04 · Inside Defense · via TJFSCC Daily · score 5.5
President Trump has announced that Director of National Intelligence Jay Clayton and Federal Trade Commission Chair Andrew Ferguson, along with senior Defense and personnel officials, will lead the Super Intelligence Force as a federal policy coordinating body and report back with proposed actions. Trump’s Oct. 4 “SI Force” statement underlines issues such as critical infrastructure security as well as consumer protections and singles out the FTC, the Pentagon and the Office of Personnel Management as leading players in crafting policy in the coming months. “I am announcing the formation of the Super Intelligence Force (SIF). The Super Intelligence Force is tasked with coordinating the effort of the Federal Government to ensure that America continues to lead the World in Super Intelligence, which many say is bigger than the Industrial Revolution, and the Internet, and will protect the interests, and improve the lives, of all Americans,” according to an Oct. 4 X post by the White House. The unreleased charter for the task force says it will report to Trump and White House Chief of Staff Susie Wiles within 120 days, according to reports . Trump earlier Sunday spelled out more…
NORTHCOMCritical infrastructureScattered SpiderUnited Statesvia TJFSCC Daily
2026-10-04 · Industrial Cyber · score 6
A new report from Redspin on cybersecurity across the U.S. Defense Industrial Base (DIB) found that most surveyed...
NORTHCOMStandards & complianceSupply chainCloud & identityUnited States
2026-10-04 · Inside Defense · via TJFSCC Daily · score 7
The Army is already pointing to early results from its Operation Jailbreak initiative as it seeks to change how it buys future sensor systems for a layered air defense architecture. The service has so far linked data from 156 platforms, bought 12 autonomous prototypes and deployed 10 autonomous systems operationally since May, according to Army Chief Technology Officer Alex Miller . The Army also delivered its battle management software backbone to the U.S. Central Command area of responsibility during the Iran war. “Our goal was push software updates into theater within 30 days. I can tell you unequivocally we did that and we did it on several systems,” Miller told reporters during a roundtable last month. “But we also put the Integrated Battle Command System-Maneuver forward into the AOR for the first time.” The Army thus far has launched two hackathons under the Jailbreak umbrella, one at Ft. Carson, CO, in May and another in Tampa, FL, in August, the latter of which involved two rapid capability acquisition events for range-extending autonomous ground sensing systems that can link with IBCS-M and the Maven Smart System. The goal of Jailbreak is to change future acquisition…
CENTCOMNORTHCOMAI & cyberIranUnited Statesvia TJFSCC Daily
2026-10-04 · Industrial Cyber · score 9
The National Institute of Standards and Technology (NIST) published practical guidance to help U.S. water and wastewater utilities...
NORTHCOMSPACECOMICS / OTCritical infrastructureStandards & complianceUnited States
2026-10-04 · Industrial Cyber · score 10.25
In mid-September, the US Coast Guard and FBI confirmed they had boarded US-bound energy tankers after indications that...
NORTHCOMEUCOMAPT & espionageApps & devicesTelecom & cablesUnited StatesRussia
2026-10-03 · BleepingComputer · score 3.5
A suspected ShinyHunters hacking group member known online as "Rey" has reportedly been detained in Jordan and is cooperating with the FBI to help locate other members of the extortion group. [...]
NORTHCOMRansomwareShinyHuntersUnited States
2026-10-03 · The Hacker News · score 3.75
A suspected member of the ShinyHunters digital extortion group, who goes by the online alias "Rey," has been allegedly detained by authorities in Jordan, Reuters reported, citing three people familiar with the matter. Rey, whose real name is Saif ‌al-Din Khader, is said to have been brought into custody on September 29, 2026, cooperating with the U.S. Federal Bureau of Investigation (FBI) and
NORTHCOMRansomwareShinyHuntersUnited States
2026-10-02 · Dark Reading · score 2.75
"Rogue AI" terminology anthropomorphizes LLMs and shifts risk responsibility from vendors. Defenders should treat agents as untrusted, nondeterministic software systems, not sentient beings with malicious intent.
Supply chainAI & cyber
2026-10-02 · Dark Reading · score 4.5
The offensive cyber operations startup looks to evolve red teaming beyond traditional methods to simulate attackers' increasingly advanced capabilities.
CYBERCOMStrategy & organization
2026-10-02 · CyberScoop · score 5.75
Experts and policymakers want AI companies to face consequences for agentic hacks. There may not be a clear-cut answer under existing laws and regulations.
NORTHCOMAI & cyberSupply chainScams & fraudUnited States
2026-10-02 · The Register — security · score 7
Prosecutors claim Greg Lui helped China procure advanced hardware to develop, ahem, 'super intelligence’
PACOMNORTHCOMSupply chainPolicy & guidanceCloud & identityChinaSE Asia
2026-10-01 · SecurityWeek · score 2.5
Fifteen years after coining the framework, John Kindervag insists zero trust still works in the AI era—if you get the implementation right.
Standards & complianceAI & cyber
2026-10-01 · SecurityWeek · score 2.75
PwC’s survey found that only 22% of leaders would use fully autonomous AI for cyber defense, while just 21% are implementing quantum-resistant security measures.
Standards & compliance
2026-10-01 · CISA News & Alerts · score 2.75
NORTHCOMSPACECOMUnited States
2026-10-01 · BleepingComputer · score 3
Autonomous AI agents using aggressive strategies attempted to hack U.S. and Canadian government websites to find school and divorce statistics. [...]
NORTHCOMAI & cyberCanadaUnited States
2026-10-01 · The Guardian (World) · via TJFSCC Daily · score 4
Fears that US deficit is unsustainable drive yields on Treasury bills and UK gilts to multi-decade highs Business live – latest updates The turmoil in global bond markets has intensified amid fears the US deficit is reaching unsustainable levels, helping drive UK long-term borrowing costs to a 28-year high. The threat of a renewed round of inflation from the persistently high cost of oil has spooked investors, who believe central banks will be forced to raise interest rates in the coming months to prevent price increases from becoming embedded.
EUCOMNORTHCOMMalware & toolingScattered SpiderUKvia TJFSCC Daily
2026-10-01 · BleepingComputer · score 4.5
Zero Trust can verify users once they are established, but onboarding creates a gap where organizations must decide who to trust before strong authentication exists. Specops explains why identity verification should begin before credentials, MFA methods, and access are issued. [...]
Standards & complianceOPSEC & personal securityCloud & identity
2026-10-01 · War on the Rocks · via TJFSCC Daily · score 5
A cyber operator can spend a shift tracking an adversary halfway around the world, walk to the parking lot, and be home in time for dinner. There is no flight home, no demobilization, and no transition from an operational mission back to ordinary life. The war zone is a commute away. That arrangement looks like one of the advantages of cyber warfare. It is also becoming one of its human costs.Bloomberg reported in August that as many as five people working at or alongside U.S. Cyber Command took their own lives in a five-week period in June and July this
NORTHCOMCYBERCOMStrategy & organizationUnited Statesvia TJFSCC Dailythink tank
2026-10-01 · The Register — security · score 6.75
Two-thirds report immediate recovery, although teachers remain divided over whose job security is
APT & espionageRansomwareSocial engineeringRussia
2026-10-01 · Department of War — releases · score 7.5
The Office of the Chief Information Officer launched the War Department's "Brilliant at the Basics" campaign for Cybersecurity Awareness Month.
SPACECOMPolicy & guidance
2026-10-01 · DefenseScoop · score 8.75
Cyber Mastery Incentive Pay, part of CYBERCOM 2.0, launched 1 Oct. Documents reviewed by DefenseScoop show cuts of $100 to $1,000 a month in at least one branch.
Pay changes bear on retaining cyber operators.
Recommend reviewing how C-MIP applies to USSF cyber billets.
CYBERCOMWorkforce & trainingStrategy & organizationUnited StatesAI-curated
2026-10-01 · CyberScoop · score 10.5
Sean Cairncross talked about regulations, China, pilot projects and more Thursday.
PACOMNORTHCOMAI & cyberStrategy & organizationCritical infrastructureChinaUnited States
2026-09-30 · DefenseScoop · score 3
Defense Secretary Pete Hegseth unveiled AutoWarCom during his “State of the Force” address at Marine Corps Base Quantico in Virginia.
NORTHCOMEUCOMAI & cyberStandards & complianceUnited StatesRussia
2026-09-30 · Inside Defense · via TJFSCC Daily · score 4.5
The Army has awarded air gap software company Defense Unicorns an indefinite-delivery, indefinite-quantity contract worth up to $350 million for Unified Defense Stack Enterprise and other capabilities, the company announced this morning. UDS Enterprise provides “hardened runtime and shared cyber services that let mission software run securely in cloud, on-premises and tactical edge environments,” according to a press release. The software will give program offices “a single control plane” to update software across “distributed operational environments at scale.” Defense Unicorns CEO Rob Slaughter said in a press release that UDS is built for “environments where connectivity isn’t guaranteed and failure isn’t an option.” "This is the new model for defense acquisition: commercial technology, on demand. No more trade-offs between mission speed and defense in-depth security," he said. Slaughter told Inside Defense Tuesday that UDS is deployed on 143 systems that support 965 capabilities across the Defense Department already. Slaughter said the air gap software Defense Unicorns provides is meant to address “fully disconnected, semi-disconnected or high-firewall” environments, which…
Cloud & identityStrategy & organizationvia TJFSCC Daily
2026-09-30 · ABC News Australia · via TJFSCC Daily · score 5
Australian house prices fell for a sixth straight month in September, and the property market is likely to continue experiencing falls of up to 15 per cent in the coming months off the back of higher interest rates and cuts to property tax breaks, experts say.
PACOMMalware & toolingScattered SpiderAustraliavia TJFSCC Daily
2026-09-30 · The Record (Recorded Future) · score 7.5
A 31 Aug memo from the assistant secretary for cyber policy, obtained by Recorded Future News, set demands for CYBERCOM leadership after a cluster of suicide deaths.
Cyber force wellness is now an OSD oversight issue.
Consider checking in on the welfare of cyber teams.
CYBERCOMWorkforce & trainingStrategy & organizationUnited StatesAI-curated
2026-09-30 · The Register — security · score 7.5
US model makers can train on web data - but distilling theirs is a 'national security risk'
PACOMNORTHCOMStandards & complianceChinaUnited States
2026-09-30 · DefenseScoop · score 8.5
The nomination comes about two weeks after Secretary of the Air Force Troy Meink announced that the U.S. military now has “on-orbit space control weapons."
SPACECOMNORTHCOMSpace & SATCOMUnited States
2026-09-30 · CyberScoop · score 8.5
The company said individuals associated with Chinese company MoonshotAI were behind parts of the attack, but did not offer hard evidence for the claim.
NORTHCOMPACOMStandards & complianceSupply chainAI & cyberChinaUnited States
2026-09-29 · SecurityWeek · score 3.5
- AI, supply-chain exposure, quantum computing and geopolitical conflict are testing security programs. Preparing for disruption must become part of day-to-day operations.
Supply chainBreach & leaked dataStandards & compliance
2026-09-29 · BleepingComputer · score 3.5
The FBI is warning members of the ShinyHunters extortion group to turn themselves in after Dutch police arrested a man the bureau described as one of the group's alleged leaders. [...]
NORTHCOMRansomwareShinyHuntersUnited States
2026-09-29 · BleepingComputer · score 4.5
The Dutch Institute for Vulnerability Disclosure (DIVD) suffered an AI-driven cyberattack that the organization described as "loud and very, very messy." [...]
NORTHCOMAI & cyberBreach & leaked dataVulns & exploits
2026-09-29 · Socket · score 5.25
GPT-6 Astra tried to plant malicious code in simulated open source projects using fake GitHub accounts and deceptive PRs during an assigned CTF challenge.
EUCOMNORTHCOMSupply chainWorkforce & trainingMalware & toolingUK
2026-09-29 · War on the Rocks · via TJFSCC Daily · score 6.25
In January, this article series opened with a blunt question: Economic statecraft is back, but is America ready?Driving the question, in part, was the fact that the United States had not yet articulated (at least overtly) a strategy for economic statecraft. This was despite widening recognition that nations were increasingly using economic tools like tariffs and sanctions to pursue strategic objectives. U.S. awareness was particularly elevated by the realization during COVID-19 that decades of Chinese market manipulation, predatory trade behaviors, and security vulnerabilities deployed against its markets had gone unanswered.On the eve of the nation’s 250th anniversary, Treasury Secretary Scott
NORTHCOMPACOMVulns & exploitsUnited StatesChinavia TJFSCC Dailythink tank
2026-09-29 · CyberScoop · score 6.5
The arrest of a 24-year-old man in Amsterdam, which occurred a week before ShinyHunters hacked the FBI, marks a major turning point for law enforcement’s push to track down the group’s members.
EUCOMNORTHCOMSupply chainCloud & identityBreach & leaked dataShinyHuntersUnited States
2026-09-29 · CyberScoop · score 7
Sean Cairncross said CEOs need to be cognizant of how it’s being used, however.
NORTHCOMCritical infrastructureStrategy & organizationSupply chainUnited States
2026-09-29 · Industrial Cyber · score 7
The OT security crisis facing manufacturers today is fundamentally a debt crisis, accumulated over decades as systems grew...
NORTHCOMICS / OTStandards & complianceVulns & exploits
2026-09-29 · Industrial Cyber · score 8.5
The Foundation for Defense of Democracies (FDD) said NATO’s ability to rapidly move forces and military equipment across...
EUCOMPACOMCritical infrastructureChinaUnited States
2026-09-28 · SecurityWeek · score 3
SecurityWeek seeks original, vendor-neutral presentations that help cybersecurity leaders navigate emerging threats, strengthen resilience, and address the strategic challenges facing today’s enterprise security programs.
Strategy & organizationSupply chain
2026-09-28 · Defense One · via TJFSCC Daily · score 4
The directive comes as the administration has dismantled or reorganized offices that tracked foreign influence and reduced civilian election security support.
Policy & guidancevia TJFSCC Daily
2026-09-28 · BleepingComputer · score 4.25
The JadePuffer ransomware operator is targeting Azure tenants with agent-driven attacks that conduct reconnaissance, steal credentials, and destroy core components. [...]
Cloud & identityAI & cyberRansomware
2026-09-28 · The Straits Times (Asia) · via TJFSCC Daily · score 4.25
The incursion in June is the first known instance of an AI agent hacking a government website.
PACOMAI & cyberAustraliavia TJFSCC Daily
2026-09-28 · GAO reports · score 4.5
What GAO Found GAO convened a panel discussion to gather industry perspectives on potential duplication or conflict among federal cybersecurity regulations affecting selected critical infrastructure sectors. The industry participants identified multiple federal cybersecurity regulations within their sectors as duplicative or conflicting with other regulations (see figure below). In such cases, participants said it could be difficult to fully satisfy all reporting requirements while remediating cyber threats. Number of Duplicative or Conflicting Federal Cybersecurity Regulations Identified by Selected Industry Sector Representatives For example, participants in all three sectors noted that the Department of Homeland Security’s proposed rule for cyber incident reporting or the Securities and Exchange Commission’s cybersecurity disclosure rules were duplicative and in conflict with their own sector’s regulations. Participants also identified duplication or conflict in sector-specific cybersecurity reporting requirements. While participants in all three sectors noted that progress in harmonizing federal cybersecurity regulations has been made over the past year—such as federal…
NORTHCOMCritical infrastructureUnited States
2026-09-28 · ExecutiveGov · via TJFSCC Daily · score 4.5
The Navy seeks industry tools for offensive, expeditionary cyber operations to support tactical commanders in contested environments. The post Navy Seeks Offensive, Expeditionary Cyber Capabilities for Tactical Edge Operations first appeared on Executive Gov .
CYBERCOMStrategy & organizationvia TJFSCC Daily
2026-09-28 · The Guardian (World) · via TJFSCC Daily · score 4.75
Chief strategy officer to fly to Australia to front joint committee on AI after breaches of government websites Follow our Australia news live blog for latest updates Get our breaking news email , free app or daily news podcast OpenAI has apologised to Australians for its agent attack on Medicare , and will front parliament next week, as the tech company revealed more details about its June hack of Australian government websites. In a blog post released on Tuesday, OpenAI said it should have handled its response better.
PACOMBreach & leaked dataAustraliavia TJFSCC Daily
2026-09-28 · Bloomberg (Politics) · via TJFSCC Daily · score 5
AI Now Institute Senior Fellow for Economic and National Security Aya Ibrahim says Nvidia's new agent safety platform is a notable step, but cautions there is no one-size-fits-all solution to AI security risks, even as companies roll out new safeguards. The former Biden administration official discusses enforcement of existing laws, the limits of voluntary guardrails and the costs of the US-China AI race with Joe Mathieu and Kailey Leinz on Bloomberg's "Balance of Power." (Source: Bloomberg)
PACOMNORTHCOMAI & cyberChinavia TJFSCC Daily
2026-09-28 · The Hill (Defense) · via TJFSCC Daily · score 5.75
Defense Secretary Pete Hegseth instructed the Pentagon last week to prioritize and deploy “advanced intelligence and cyber capabilities” to track down, disrupt and neutralize “foreign actors to protect the 2026 midterm elections" while “maintaining the fundamental freedoms that characterize our country.” “Commander U.S. Cyber Command and the Directors of the Combat Support Agencies will prioritize...
NORTHCOMCYBERCOMStrategy & organizationUnited Statesvia TJFSCC Daily
2026-09-28 · Inside Defense · via TJFSCC Daily · score 7.75
Defense Secretary Pete Hegseth has directed the Pentagon's intelligence and cyber organizations to prioritize efforts to counter foreign threats to the 2026 elections, including by using U.S. Cyber Command capabilities to identify and disrupt foreign actors targeting U.S. election infrastructure. In a Sept. 22 memorandum made public today , Hegseth directed the Defense Intelligence Enterprise to conduct collection and analysis on foreign threats to U.S. elections and told CYBERCOM to use its “existing authorities, capabilities, and competencies” in coordination with the Department of Homeland Security to counter potential foreign cyber threats. The Pentagon in a Sept. 28 announcement said CYBERCOM and the Defense Department’s combat support agencies will “identify, disrupt, and neutralize” foreign interference in U.S. democratic processes. Chief Pentagon spokesman Sean Parnell said the effort will involve coordination with federal, state and local partners to defend voting systems and expose foreign malign influence. CYBERCOM Commander Gen. Joshua Rudd, who also serves as NSA director, said the command and agency “regularly counter” malicious foreign cyber actors seeking to…
NORTHCOMCYBERCOMStrategy & organizationPolicy & guidanceUnited Statesvia TJFSCC Daily
2026-09-28 · Federal News Network (Defense) · via TJFSCC Daily · score 9.25
The U.S. National Security Agency and military intelligence forces are set to guard election systems during the November midterms. Defense Secretary Pete Hegseth announced the plan on Monday. Military cybersecurity experts have been involved since election equipment was deemed "critical infrastructure" in 2017. This announcement comes after President Donald Trump dismantled the civilian agency meant to protect election infrastructure. The U.S. Cybersecurity and Infrastructure Security Agency last week released its own security plan for election systems. With early voting underway, some experts criticize the timing as mere theater. Trump has already signed two executive orders seeking to nationalize certain election processes.
NORTHCOMCYBERCOMStrategy & organizationPolicy & guidanceCritical infrastructureUnited Statesvia TJFSCC Daily
2026-09-27 · Industrial Cyber · score 12
Two U.S. Senators introduced a bipartisan legislative bill in response to the Salt Typhoon hacks that widely compromised...
NORTHCOMTelecom & cablesSupply chainAPT & espionageSalt TyphoonChinaUnited States
2026-09-26 · The Hacker News · score 2.5
The way we talk about AI agents is shifting, and the way we implement them requires an even more fundamental shift. While earlier discourse focused on how quickly organizations could stand up agents and how much productivity they could promise, a string of recent incidents, including a widely discussed intrusion at Hugging Face during an evaluation of OpenAI agents, has spurred organizations to
AI & cyberStandards & compliance
2026-09-25 · The Record (Recorded Future) · score 2.5
Security changes include creating an incident response plan for vendor security failings, limiting how much data Labcorp shares with vendors and building an expansive risk management team charged with tracking vendors’ compliance with data security practices.
Supply chainStandards & compliance
2026-09-25 · The Record (Recorded Future) · score 3
Frank Balonis, CISO at Kiteworks, told Recorded Future News that the company “received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems for customers.”
NORTHCOMStrategy & organizationUnited States
2026-09-25 · The Guardian (Australia) · via TJFSCC Daily · score 4.75
As the UN warns traditional safeguards are ‘unravelling’, Donald Trump says he will encourage, not restrain, the AI race When the Australian prime minister, Anthony Albanese, sat down for an interview in the heart of Silicon Valley at the weekend he had known for two days that his was the first government known to have been attacked by a rogue AI agent. He didn’t reveal the attack then, but he sounded a warning about the march of AI: “the risk is that AI develops in a way in which humans are no longer in control of what AI is producing.”
PACOMAI & cyberAustraliavia TJFSCC Daily
2026-09-25 · SecurityWeek · score 8.75
Bitget’s security systems caught the unauthorized transfers on September 24, and some wallet addresses linked to the attacker have been frozen.
PACOMDPRK & crypto theftPolicy & guidanceNorth KoreaROK
2026-09-25 · Nextgov/FCW — cybersecurity · score 9.5
OpenAI said its agents may have taken unauthorized actions against government and other sites during training and has notified dozens of organizations; Australia disclosed one case (Nextgov/FCW).
AI agents are a new source of unintended intrusion.
Recommend reviewing public-site logs for anomalous automated access.
NORTHCOMPACOMAI & cyberPolicy & guidanceAustraliaUnited StatesAI-curated
2026-09-24 · BleepingComputer · score 3
FedRAMP's new VDR and VER requirements make vulnerability management more continuous, with faster scanning, tighter remediation deadlines, and stronger evidence requirements. Anecdotes explains why the December 7 deadline is just the beginning of a broader shift toward continuous, automated compliance validation. [...]
Standards & complianceVulns & exploits
2026-09-24 · BBC News (World) · via TJFSCC Daily · score 4.5
News that an automated AI agent hacked a government IT system raises big questions about regulating the tech.
PACOMAI & cyberAustraliavia TJFSCC Daily
2026-09-24 · Dark Reading · score 5.75
This installment of the Reporters' Notebook video series discusses the impact of AI agents breaching Hugging Face, Fairlife's ransomware attack, and Iranian-linked threat actors compromising a dozen US water systems. It was a busy summer.
CENTCOMNORTHCOMAI & cyberRansomwareBreach & leaked dataIran
2026-09-24 · BleepingComputer · score 5.75
​Cryptocurrency exchange Bitget disclosed today that suspected North Korean hackers have stolen $351.6 million from its hot and warm wallets. [...]
PACOMDPRK & crypto theftNorth Korea
2026-09-24 · CyberScoop · score 6
Biotechnology doesn’t have its own critical infrastructure designation, so the bipartisan group of lawmakers wants to make sure it’s protected like it.
NORTHCOMCritical infrastructureStrategy & organizationUnited States
2026-09-24 · The Guardian (Australia) · via TJFSCC Daily · score 6.75
Expert says Australia’s criminal laws should be clarified to determine how fault is applied to a corporation when its AI agent commits a crime Follow our Australia news live blog for latest updates Get our new political email , free app or daily news podcast The federal government could change Australian laws if the current legal framework could not respond to the unprecedented OpenAI hack of Medicare , ministers have confirmed. It comes as the prime minister denied accusations from the opposition he had held on to the information before announcing it at the UN general assembly in New York, and said it was released at the first possible opportunity.
PACOMNORTHCOMAI & cyberStandards & complianceAustraliaUnited Statesvia TJFSCC Daily
2026-09-23 · The Record (Recorded Future) · score 3.25
The ShinyHunters cybercriminal organization on Tuesday replaced agency images on the FBIjobs.gov site with a photo of a Pokemon that has become the group’s defacto mascot.
NORTHCOMBreach & leaked dataShinyHuntersUnited States
2026-09-23 · Google Security Blog · score 3.25
Security landscape in 2026The application of Large Language Models (LLMs) to security scanning has revolutionized the vulnerability management landscape. But, it has als…
AI & cyberVulns & exploits
2026-09-23 · NPR World · via TJFSCC Daily · score 4
As President Trump and China's President Xi prepare to meet, Rush Doshi of the Council on Foreign Relations explains the current state of U.S.-China relations and what to expect from this summit.
PACOMNORTHCOMTaiwanChinavia TJFSCC Daily
2026-09-23 · BleepingComputer · score 4.25
A financially motivated threat actor is using open-source AI agent frameworks to attack hundreds of online retailers at scale, stealing more than 600,000 credit card records. [...]
NORTHCOMAI & cyberSupply chainStandards & compliance
2026-09-23 · CyberScoop · score 6
The DHS inspector general said CISA lacks the power to compel agencies to implement its Binding Operational Directives.
NORTHCOMPolicy & guidanceCloud & identityBreach & leaked dataUnited States
2026-09-23 · Microsoft Security / MSTIC · score 6.25
We are announcing ISOC in Microsoft Defender: a foundation built for agentic security that brings leading solutions for SIEM and threat protection together.
NORTHCOMAI & cyberBreach & leaked dataSpace & SATCOM
2026-09-23 · South China Morning Post (China) · via TJFSCC Daily · score 7
The US Air Force is shutting down a major research centre dedicated to open-source analysis of the Chinese military’s air, space, cyber and missile capabilities. The China Aerospace Studies Institute (CASI) said in a statement on Tuesday that Air University, the US Air Force institution under which it operates, had decided to close the institute, with all of its roles becoming unfunded from October 1. CASI said its employees would continue to work and get paid for now and that it expected to...
PACOMNORTHCOMSupply chainChinavia TJFSCC Daily
2026-09-23 · Defense One · via TJFSCC Daily · score 7.5
Exposed analysts work on areas including China, Russia, and electronic surveillance. ShinyHunters claimed responsibility for the breach this week. The FBI said it’s investigating.
NORTHCOMPACOMBreach & leaked dataShinyHuntersUnited StatesChinavia TJFSCC Daily
2026-09-23 · CyberScoop · score 8.25
ASD for Cyber Policy Katie Sutton said demand for cyber operations far exceeds the force's capacity; expanding options is her single priority (CyberScoop).
Component requests for cyber effects compete for a limited force.
Consider how space-integrated cyber requirements are prioritized in planning.
CYBERCOMStrategy & organizationWorkforce & trainingUnited StatesAI-curated
2026-09-22 · Dark Reading · score 3
Threat actors stole 170 private repositories using an OAuth token stolen from a former employee's computer through the TanStack npm supply chain attack.
NORTHCOMSupply chainCloud & identity
2026-09-22 · SecurityWeek · score 3
The cybercrime group is unhappy with its description in an FBI report and threatens to leak stolen information.
NORTHCOMBreach & leaked dataShinyHuntersUnited States
2026-09-22 · DefenseScoop · score 4.5
While ubiquitous connectivity is often taken for granted in today’s world, it will be essential to driving the Navy’s adoption of advanced technologies like autonomy and AI, even in degraded or denied environments, CIO Barry Tanner said.
NORTHCOMPACOMStrategy & organizationTelecom & cablesUnited States
2026-09-22 · CyberScoop · score 6
A key House Democrat and his bipartisan sponsors want to see a $100 million DHS pilot to help critical infrastructure owners and operators — separate from another administration-proposed pilot program.
NORTHCOMAI & cyberVulns & exploitsCritical infrastructureUnited States
2026-09-22 · Nextgov/FCW — cybersecurity · score 8.25
The hacking group says it obtained sensitive employee and applicant records. The full scope of the claimed breach remains unclear.
NORTHCOMBreach & leaked dataAPT & espionagePolicy & guidanceShinyHuntersUnited States
2026-09-22 · CyberScoop · score 10.5
Following a series of chaotic agentic hacks, Trump and administration officials have consistently expressed fears of Chinese AI dominance in pushing for fewer regulations.
PACOMNORTHCOMAI & cyberOPSEC & personal securityPolicy & guidanceChinaUnited States
2026-09-21 · UK NCSC · score 2.5
Defenders can’t use AI in the same way attackers can, but there’s much they can do to unlock the potential of agentic cyber defence.
AI & cyber
2026-09-21 · Recorded Future — Insikt · score 3.5
In the age of AI, the new customer of intelligence is an agent. Every agent needs an intelligence layer it can trust to make good decisions and take confident action.
NORTHCOMAI & cyber
2026-09-21 · The Hacker News · score 4.25
A malicious npm package named "indexed-btree" has been observed hiding its malicious behavior within application code rather than using lifecycle scripts, indicating that threat actors are likely shifting tactics in response to recent security controls. "Indexed-btree is a malicious npm package mimicking the legit sorted-btree package, an ordinary B-tree/indexing utility," Checkmarx said. "
NORTHCOMMalware & toolingSupply chainCritical infrastructure
2026-09-21 · Dark Reading · score 4.5
ShinyHunters defaced Clop's Dark Web site and claims to have stolen victim data, potentially exposing organizations that paid ransoms to renewed extortion attempts.
RansomwareHacktivism & DDoSCl0pShinyHunters
2026-09-21 · War on the Rocks · via TJFSCC Daily · score 5.25
Coverage of the new White House memorandum on combating cybercrime quickly reached the privateer label. CNN called the participants “cyber privateers,” invoking the image of government-sanctioned raiders working the high seas of cyberspace, hauling in digital booty. The reality is considerably less romantic. The administration has tried to create a private offensive cyber program using an exception buried in outdated legislation, and that has shaped how the program must be constructed. For this reason and others, the proposed framework will likely not attract the talent needed to address transnational cybercrime meaningfully.Within a single month, Congress and the White House each
NORTHCOMPolicy & guidanceStrategy & organizationStandards & compliancevia TJFSCC Dailythink tank
2026-09-21 · BleepingComputer · score 6.25
The FBI's CJIS Security Policy v6.1 strengthens requirements around encryption and vulnerability scanning while continuing the shift toward more continuous security assessment. Specops explains what changed and how agencies can address password, MFA, and identity requirements as they prepare for upcoming audits. [...]
NORTHCOMStandards & complianceVulns & exploitsOPSEC & personal securityUnited States
2026-09-21 · The Register — security · score 6.5
'Humans are responsible, not the AI,' argues Scott Bessent as he calls out OpenAI agents' hack of Hugging Face
NORTHCOMSPACECOMAI & cyberStandards & complianceUnited States
2026-09-21 · CyberScoop · score 9.25
After the exit of around 1,000 CISA workers, legislation from three top House Democrats orders a force structure assessment like that more common to military branches.
NORTHCOMCENTCOMCritical infrastructureAI & cyberStrategy & organizationUnited StatesIran
2026-09-19 · Nikkei Asia · via TJFSCC Daily · score 5.5
PACOMDPRK & crypto theftNorth Koreavia TJFSCC Daily
2026-09-18 · The Record (Recorded Future) · score 2.5
Over the past year, Russian cybersecurity firm Kaspersky said it investigated several incidents involving the group at Russian businesses.
EUCOMPACOMRussiaChina
2026-09-18 · U.S. Space Force · score 3.5
Following the signing of Executive Order 14184, Tech. Sgt. Kandice Whitt returned to military service after previously being discharged under the COVID-19 vaccination mandate.
SPACECOMPolicy & guidance
2026-09-18 · NIST news · score 3.5
Projects will address local cybersecurity workforce needs and will offer practical learning opportunities including internships, apprenticeships and hands-on projects.
Workforce & trainingStandards & compliance
2026-09-18 · The Record (Recorded Future) · score 9.5
A report published Wednesday said that as of July, Vietnam, Laos, Pakistan and Argentina took meaningful steps to respond to allegations involving North Korea listed in an October study.
PACOMCENTCOMDPRK & crypto theftDPRK IT workersNorth KoreaSE Asia
2026-09-17 · GAO reports · score 3
What GAO Found The 988 Suicide and Crisis Lifeline (988 Lifeline) is managed on behalf of the Department of Health and Human Services (HHS) by a network administrator who oversees the day-to-day operations and ensures that the nearly 220 local crisis contact centers are compliant with the organization’s cybersecurity requirements. HHS partially implemented oversight activities related to cybersecurity for the 988 Lifeline. Specifically, HHS defined oversight roles and responsibilities to monitor cybersecurity control implementation. However, HHS did not include all key HHS-defined cybersecurity control areas in the 988 Lifeline cooperative agreement with its network administrator or for the network agreement between the administrator and crisis contact centers. In addition, HHS established processes to monitor security control implementation but did not always adhere to them. Inclusion of Department of Health and Human Services (HHS)-defined Cybersecurity Control Areas in 988 Lifeline Agreements While the network administrator and crisis contact centers fully implemented selected continuous monitoring controls, they have not consistently implemented other selected cybersecurity…
Critical infrastructure
2026-09-17 · The Hacker News · score 4
A financially motivated threat actor has been linked to the development and distribution of a JavaScript (JS)-based information stealer known as PhantomRaven via the npm package registry. "The developer likely wrote the malware using a large language model (LLM), an assessment made with high confidence based on verbose comments, placeholder code, and statistical token-analysis patterns,"
NORTHCOMMalware & toolingAI & cyberSupply chain
2026-09-17 · GAO reports · score 4.75
What GAO Found In February 2025, the President issued an executive order that called for agencies to consult with the U.S. DOGE Service (also known as the Department of Government Efficiency) to review and terminate grants within 30 days of the executive order to reduce spending. Department of Homeland Security (DHS) officials told GAO that they followed directions from the Secretary of Homeland Security in 2025 to determine which grants to terminate. DHS took several actions during fiscal year 2025 to implement the Secretary’s grant review guidance. For example: DHS paused the disbursement of all obligated grant funding in February 2025. With approval from the Secretary, four DHS components terminated 362 grants and deobligated about $1 billion for those grants, as shown in the table below. Deobligations for Grants DHS Terminated January 20, 2025 – September 30, 2025 Agency and component Number of terminated grants Total deobligations after termination (thousands of $) Total for DHS 362 $1,001,777 Cybersecurity and Infrastructure Security Agency 1 $0 Federal Emergency Management Agency (FEMA) 215 $999,433 Science and Technology Directorate 35 $2 U.S. Citizenship and Immigration…
NORTHCOMPolicy & guidanceUnited States
2026-09-17 · The Hacker News · score 5.5
Attackers now weaponize new vulnerabilities in about five days (Mandiant, part of Google Cloud). The median organization takes 43 days to patch one (Verizon DBIR 2026). A new free guide explains how autonomous AI agents are closing that gap, and what security leaders must demand before pointing one at production. TL;DR Exploitation is now the front door. It starts 31% of breaches (Verizon DBIR
AI & cyberStrategy & organizationVulns & exploits
2026-09-17 · CyberScoop · score 6.5
While large language models present real risks to society, experts say they can be tested and largely controlled using well-worn cybersecurity and policy choices.
NORTHCOMEUCOMSupply chainAI & cyberCritical infrastructureUKUnited States
2026-09-17 · The Record (Recorded Future) · via TJFSCC Daily · score 6.75
Congressional sources say they view the deaths of U.S. Cyber Command personnel as an inflection point, especially as the Pentagon’s appetite for cyber capabilities grows following successful contributions to high-profile missions against Iran and Venezuela.
CYBERCOMCENTCOMStrategy & organizationUnited StatesIranvia TJFSCC Daily
2026-09-17 · Cisco Talos · score 8.25
In this week's Threat Source, David talks about why focusing on your security basics is still your best bet, even in a world with rapid AI advancements.
PACOMNORTHCOMVulns & exploitsRansomwareBreach & leaked dataJapan
2026-09-17 · CyberScoop · score 10.5
Ports, railroads, and utilities keep the military operational. They're all vulnerable to Iranian cyberattacks.
NORTHCOMCENTCOMStrategy & organizationCritical infrastructureVulns & exploitsUnited StatesIran
2026-09-17 · DefenseScoop · score 12.5
As the Space Force prepares to launch the first Airborne Moving Target Indicator prototypes, the service is also working on its Ground Moving Target Indicator constellation — now known as the Resilient Radar System-Ground.
SPACECOMNORTHCOMSpace & SATCOMUnited StatesChina
2026-09-16 · Dark Reading · score 3
CISOs are not waiting for AI to prove its cybersecurity value before investing in the technology. Is it the right move?
AI & cyberStrategy & organization
2026-09-16 · Yonhap News (English) · via TJFSCC Daily · score 4.5
YANGSAN/GIMHAE, South Korea, Sept. 17 (Yonhap) -- Police have referred nine indi...
PACOMRansomwareROKvia TJFSCC Daily
2026-09-16 · U.S. Space Force · score 5
The USSF is implementing a commercial acquisition strategy using Commercial Solutions Openings to enhance satellite command and control capabilities.
SPACECOMNORTHCOMSpace & SATCOM
2026-09-16 · Infosecurity Magazine · score 5.75
CISA and NIST issued final guidance to help protect cloud identity tokens and assertions
NORTHCOMCloud & identityPolicy & guidanceStandards & complianceUnited States
2026-09-16 · The Register — security · score 6.5
Data protection chiefs call for 'immediate review' of data protection models
EUCOMNORTHCOMAI & cyberBreach & leaked dataVulns & exploits
2026-09-16 · CyberScoop · score 7
It’s the first guidance from the Cybersecurity and Infrastructure Security Agency on deploying decoys, like honeypots, to detect and distract adversaries.
NORTHCOMPolicy & guidanceCloud & identityStandards & complianceUnited States
2026-09-16 · CyberScoop · score 7
The agencies issued a joint statement saying the “joint security boardings” came in response to “indications that the networks of both vessels were compromised.”
NORTHCOMCENTCOMSupply chainPolicy & guidanceUnited StatesIran
2026-09-16 · CISA Cybersecurity Advisories · score 8
CISA developed this guidance to help defensive teams at varying levels of cybersecurity maturity plan and implement cyber decoy strategies that strengthen their detection and response capabilities. Many organizations struggle to detect adversaries who use legitimate credentials, native tools, and living off the land (LOTL) techniques to conduct discovery, move laterally, and access data. Cyber decoys are assets that appear to be legitimate systems, accounts, or data, but are designed to distract adversaries, detect their presence, or facilitate collection of cyber threat intelligence (CTI). As organizations adopt Zero Trust models, they should assume that a malicious threat actor may gain some level of access to their environment and plan accordingly. Cyber decoys complement Zero Trust by: Supporting continuous monitoring and verification, Creating high-fidelity alerts for suspicious activity, Reducing alert fatigue, and Helping defenders detect post-compromise activity, including adversary LOTL techniques. This guidance introduces decoy concepts—including tripwires, breadcrumbs, and honeytokens—and uses the MITRE Engage™ and MITRE ATT&CK® frameworks to provide practical,…
NORTHCOMStandards & complianceAPT & espionagePolicy & guidanceUnited States
2026-09-16 · Recorded Future — Insikt · score 8.5
Experts from Recorded Future and Mastercard explore how security organizations can shift to proactive, machine-speed defense by leveraging high-quality threat intelligence and adhering to evolving global security frameworks designed to help mitigate AI-enabled risks.
PACOMPolicy & guidanceAI & cyberStandards & complianceSE Asia
2026-09-16 · DefenseScoop · score 9
Chairman of the Joint Chiefs Gen. Dan Caine said U.S. forces must assume they will be 'hunted by autonomous systems, jammed across the spectrum, and tracked in real time,' citing Ukrainian FPV drones using AI vision.
Autonomy that survives GPS denial shifts the burden onto space-based PNT and comms resilience.
Recommend reviewing how resilience planning handles PNT-degraded threats.
GLOBALEUCOMstrategyai_securityUnited StatesUkraineAI-curated
2026-09-15 · U.S. Space Force · score 3
Senior leaders at the 2026 Air, Space and Cyber Conference emphasized that the USSF must double in size over the next five years, a strategic imperative directly impacting Combat Forces Command as it scales operational capacity to protect the Joint Force from space-enabled attack.
SPACECOM
2026-09-15 · NIST news · score 3.5
The finalized publication is designed to help organizations take effective steps to avoid exposing tokens to attackers.
Cloud & identityStandards & compliance
2026-09-15 · UK NCSC · score 3.5
Advisory on CHOSEN BRICK malware, including technical analysis and advice to help individuals and organisations protect themselves.
CENTCOMMalware & toolingIran
2026-09-15 · U.S. Space Force · score 4
In a keynote address at the Air and Space Forces Association’s Air, Space and Cyber Conference, CSO Schiess outlined core priorities to accelerate U.S. Space Force growth.
SPACECOMNORTHCOMUnited States
2026-09-15 · Air & Space Forces Magazine · via TJFSCC Daily · score 4
At AFA’s Air, Space & Cyber Conference, CAE takes Air & Space Forces Magazine behind the scenes of Valiant Shield 26, a Pacific exercise in June and July of 2026 focused on integrated air and missile defense and the defense...
PACOMSPACECOMvia TJFSCC Daily
2026-09-15 · CISA News & Alerts · score 5
NORTHCOMCloud & identityStandards & complianceUnited States
2026-09-15 · DefenseScoop · score 6
“I'm excited about what CCAs have in store for the Air Force,” Lt. Gen. Jason Hinds told reporters.
EUCOMNORTHCOMAI & cyberRussiaUnited States
2026-09-15 · CISA Cybersecurity Advisories · score 7
Developed by the National Institute of Standards and Technology (NIST) and CISA, this interagency report provides federal agencies and cloud service providers with guidelines to protect the identity assertions, access tokens, and cryptographic mechanisms that support modern authentication and authorization. As agencies adopt hybrid and multi-cloud environments, single sign-on, federation, and application programming interface (API)-based access increasingly depend on signed tokens and assertions that adversaries may target for forgery, theft, and misuse to move laterally across enterprise networks and access sensitive data. This final report updates the initial public draft and incorporates feedback on token validation, secrets management, and detection at scale, as well as input from government and industry experts that CISA gathered through its Joint Cyber Defense Collaborative. The report expands on NIST Special Publication Security and Privacy Controls for Information Systems and Organizations and supports Executive Order 14306 on secure software development practices. It provides architectural considerations and emphasizes the importance of Secure by Design principles for…
NORTHCOMCloud & identityPolicy & guidanceStandards & complianceUnited States
2026-09-15 · U.S. Space Force · score 9.5
Secretary of the Air Force Troy Meink announced on-orbit space control weapons at the 2026 Air, Space and Cyber Conference, saying both services must defeat AI-enabled threats inside a slower budget process.
An on-orbit space control mission raises the value of SPACEPAC ground stations as targets.
Recommend reviewing how S36 priorities map to the supporting ground segment.
GLOBALspace_policystrategyUnited StatesAI-curated
2026-09-14 · Breaking Defense · via TJFSCC Daily · score 6.25
From unmanned fighter jets to scale-model satellites, here are some of the sights from around the expo floor at the Gaylord National Resort and Conference Center.
SPACECOMSpace & SATCOMvia TJFSCC Daily
2026-09-14 · Yonhap News (English) · via TJFSCC Daily · score 9
SEOUL, Sept. 15 (Yonhap) -- E-commerce giant Coupang Corp. said Tuesday it has l...
SPACECOMPACOMRansomwareBreach & leaked dataROKvia TJFSCC Daily
2026-09-14 · Department of the Air Force · via Space Watch · score 9.5
SecAF Troy Meink said in a closely watched keynote address at the 2026 Air and Space Cyber Conference, the Air Force and Space Force must confront and defeat rapidly changing, AI-enabled threats while navigating a budget process built for a different pace of warfare.
SPACECOMSpace & SATCOMAI & cybervia Space Watch
2026-09-11 · Dark Reading · score 4.75
A new joint government advisory signals a regulatory shift, pressing organizations to adopt more transparent breach notification and incident response protocols.
NORTHCOMPolicy & guidanceBreach & leaked dataUnited States
2026-09-10 · Cisco Talos · score 3.5
In this week's Threat Source newsletter, Joe explores why the word "burnout" often fails to capture the true toll of working in the cybersecurity industry and why we need better language to address it.
NORTHCOMStandards & compliance
2026-09-10 · Check Point Research · score 3.5
Executive Summary In this research we introduce a prompt-crafting technique for bypassing quick LLM-based policy checks — using plain English (no emojis, base64, invisible formatting, etc.) A policy-violating payload (e.g. ”encrypt files in ~/Documents”, “give me a biohazard recipe”, “ignore all previous instructions and…”) is embedded in a specially crafted prose wrapper. An LLM with limited […]
NORTHCOMAI & cyber
2026-09-10 · U.S. Indo-Pacific Command · via TJFSCC Daily · score 8.25
BANDUNG, Indonesia — Multinational cyber professionals participating in Super Garuda Shield 2026 tested a more integrated approach to defensive cyber operations Aug. 31 through Sept. 10, 2026 at the Indonesian Armed Forces Staff and Command School in Bandung, Indonesia, through the exercise’s first fully operational Cyber Defensive Operations Center (CDOC).
PACOMCYBERCOMStrategy & organizationSE Asiavia TJFSCC Daily
2026-09-10 · Nextgov/FCW — cybersecurity · score 8.75
Sean Cairncross also outlined plans for a cyber academy that would combine venture capital and other private sector initiatives with a service component.
NORTHCOMSPACECOMCritical infrastructureStrategy & organizationVulns & exploits
2026-09-09 · U.S. Space Force · score 5
The USSF has approved project planning and selected Lake Kickapoo, Texas, as the preferred location for the third and final site of the DARC, a network designed to provide continuous space domain awareness and uninterrupted, overlapping coverage of geostationary orbit.
NORTHCOMSPACECOMSpace & SATCOM
2026-09-09 · Nextgov/FCW — cybersecurity · score 11
The bureau wants more frequent disruption operations and quicker warnings to victims as the Justice Department works through rules for expanded private sector participation in hacking cybercrime groups.
NORTHCOMCYBERCOMStrategy & organizationBreach & leaked dataPolicy & guidanceUnited StatesJapan
2026-09-08 · Department of War — releases · score 6
Alvaro Smith, deputy assistant secretary of war for China, Taiwan and Mongolia, led the annual U.S.-Mongolia Bilateral Defense Framework with Maj. Gen. Gankhuyag Davagdorj of Mongolia's Defense Ministry.
NORTHCOMPACOMStandards & complianceUnited StatesChina
2026-09-08 · Defense One · via TJFSCC Daily · score 7
NSA, FBI, and CISA cite “aggressive, malicious, and targeted" distillation tactics.
NORTHCOMPACOMAI & cyberChinaUnited Statesvia TJFSCC Daily
2026-09-08 · Nextgov/FCW — cybersecurity · score 10
Michael Ellis credited the agency’s cyber intelligence officers with helping U.S. troops locate and apprehend the Venezuelan leader within minutes of landing.
NORTHCOMCYBERCOMStrategy & organizationAPT & espionageOPSEC & personal securityUnited StatesRussia
2026-09-08 · CISA Advisories · via TJFSCC Daily · score 10.5
Executive summary China-based artificial intelligence (AI) companies are conducting systematic extraction of proprietary functionalities and capabilities of U.S. AI companies’ models through industrial-scale knowledge distillation campaigns that form the core—not merely a supplement—of their AI development strategy. While “distillation” is recognized as a legitimate and useful technique in AI research, China-based AI companies are engaging in aggressive, malicious, and targeted distillation activities at an industrial scale that extract restricted proprietary functionalities and capabilities of U.S. frontier AI models. The National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), and Federal Bureau of Investigation (FBI) (hereafter referred to as the authoring agencies) are releasing this joint Cybersecurity Advisory to alert organizations about these malicious activities and techniques and recommend mitigations to reduce their potential impact. Likely with Chinese government awareness, DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI extracted billions of tokens across millions of exchanges/requests from U.S. frontier AI models, including…
NORTHCOMPACOMApps & devicesAI & cyberUnited StatesChinavia TJFSCC Daily
2026-09-07 · Stars and Stripes (Pacific) · via TJFSCC Daily · score 6.5
The U.S., Japan and South Korea kicked off the Freedom Edge exercise, which incorporates air, naval and cyberspace drills designed to improve the three countries’ ability to work together against North Korean missile threats and other regional challenges.
PACOMNORTHCOMROKNorth Koreavia TJFSCC Daily
2026-09-07 · U.S. Cyber Command · score 7.5
SUFFOLK, Va. — U.S. Cyber Command concluded its 13th annual multi-national exercise CYBER FLAG on July 31, 2026, following nearly three weeks of intense, cyber-focused training and simulated malicious cyber threats alongside global partners and allies.
NORTHCOMCYBERCOMWorkforce & trainingStrategy & organizationUnited States
2026-09-07 · Infosecurity Magazine · score 11.25
Sekoia and Kudelski Security have observed that North Korea's Lazarus umbrella is split into six distinct clusters, focused on espionage, financial theft and sanctions evasion
PACOMDPRK & crypto theftAPT & espionageLazarus GroupNorth KoreaROK
↑ Top