Post

Cybersecurity Newsfeed - 09/10/26

Daily cybersecurity news covering vulnerabilities, adversaries, trends, breaches, and other notable security developments.

Cybersecurity Newsfeed - 09/10/26

Cybersecurity Newsfeed

📅 09/10/26

🛡️ Vulnerabilities

  • Cisco Nexus Switch Flaws Allow Complete Administrative Takeover: Cisco issued urgent advisories for critical vulnerabilities in its Nexus switch series running NX-OS software. Unauthenticated, remote attackers can execute arbitrary code with root privileges or trigger severe DoS conditions via specially crafted packets. More info

  • Critical Atlassian Vulnerability Exploited Hours After PoC: Threat actors rapidly integrated a published proof-of-concept exploit code into automated scanning tools to target unpatched Atlassian Confluence and Jira instances globally, permitting unauthenticated remote code execution. More info

  • “AgentCorruption” Vulnerability Threatens AWS AI Environments: Researchers revealed a critical flaw affecting AWS environments integrated with AI agents. Threat actors can bypass access controls, extract cloud credentials, and execute unauthorized commands via a single prompt injection attack. More info

  • Samsung Galaxy S26 Exploited Three More Times at Pwn2Own: Security researchers demonstrated zero-day input validation, privilege escalation, and remote code execution flaws affecting the baseband and core OS components of the Samsung Galaxy S26. More info

🎯 Adversaries

  • FBI Disrupts Chinese State-Sponsored Critical Infrastructure Breach: Federal law enforcement neutralized malicious infrastructure, custom malware, and compromised botnet nodes used by Chinese threat actors targeting US government, energy, and telecommunications networks. More info

  • Russian Spies Update MatchBoil Malware: Russian state-sponsored operatives deployed a facelifted variant of the MatchBoil malware family targeting diplomatic and government entities, featuring advanced anti-analysis and encrypted C2 communications. More info

  • Pro-Russian Group UAC-0099 Evolves Tactics Against Ukraine: UAC-0099 launched new spear-phishing campaigns exploiting software flaws and updated PowerShell loaders to drop persistent backdoors and exfiltrate government communications. More infoMore info
  • FakeGit Campaign Resurfaces with 17,610 Weaponized Repositories: A massive malicious software campaign automated weaponized GitHub repository creation to distribute information stealers and remote access trojans targeting software developers. More info

  • PoeLLM Malware Targets Open-Source AI Infrastructure: A malware campaign named PoeLLM was discovered uploading malicious packages to GitHub targeting AI servers, harvesting API keys, cloud credentials, and model weights. More info

  • Sixteen Malicious Firefox Add-Ons Stole User Session Data: Researchers identified sixteen malicious Firefox extensions posing as legitimate browser tools that covertly injected JavaScript to log keystrokes and capture credentials for banking and cloud services. More info

  • Cisco Talos Uncovers UAT-11985 Corporate Cyber Espionage: Threat actor group UAT-11985 is targeting corporate networks using compromised credentials, custom backdoors, credential dumping, and log suppression techniques to evade detection. More info

  • Artex AI Pentesting Framework Weaponized for Data Exfiltration: Threat actors repurposed the open-source Artex AI penetration testing framework to map target networks, execute automated privilege escalations, and exfiltrate enterprise databases. More info

  • Hunt.io Identifies New Brazetsu Banking Malware Infrastructure: Proactive telemetry and banner scanning revealed new Brazetsu C2 servers and distribution endpoints targeting financial institutions months before public vendor disclosure. More info
  • Global Cyberattacks Surge 48% Driven by Ransomware and Phishing: Check Point Research revealed a significant spike in global cyberattacks targeting education, healthcare, and government sectors, fueled by AI-driven lures and double-extortion tactics. More info

  • Ransomware Affiliates Target Identity Providers and MFA: Attackers are increasingly bypassing perimeter controls by exploiting stolen session tokens, misconfigured authentication frameworks, and conducting MFA fatigue attacks. More info

  • Accumulating OAuth Permissions Create Persistent Risks: Security experts warned of unreviewed third-party OAuth integrations being leveraged by threat actors to retain persistent, passwordless access to cloud tenants like Microsoft 365 and Google Workspace. More info

  • Low-Cost Android Phones Shipped Pre-Infected with Proxy Malware: A supply chain compromise resulted in budget Android smartphones shipping with pre-installed firmware malware that converts devices into residential proxy nodes for ad fraud and credential stuffing. More info

  • Microsoft Teams to Add Native Deepfake Detection Features: Microsoft announced integrated AI capabilities for Teams to detect synthetic audio, voice cloning, and deepfake video streams during live enterprise calls in real time. More info

  • GitHub Integrates ModernBERT AI into Secret Scanning: GitHub expanded Push Protection using ModernBERT machine learning models to detect exposed API keys, private tokens, and credentials in code prior to public commit. More info

💥 Breaches & Leaks

  • Ransomware Attack Forces IDCF Japan Cloud Offline: A severe ransomware incident impacted Japan’s Industrial Decisions Corporation Infrastructure cloud, forcing system isolation and service outages across enterprise and public sector clients. More info

  • Japan Experiences Sharp Surge in Web-Based Data Leaks: Misconfigured cloud storage, unpatched web application vulnerabilities, and credential stuffing led to a dramatic spike in corporate and government data exposures across Japan. More info

  • Ransomware and Phishing Force Small Construction Firm out of Business: A firm ceased operations after a catastrophic ransomware attack encrypted operational databases and backup drives following unpatched server exploitation and MFA-bypassing phishing. More info

  • Empire Dark Web Market Operator Sentenced to 40 Years: The administrator of Empire Market received a 40-year federal prison sentence for facilitating hundreds of millions of dollars in illicit drug, weapon, and cybercrime transactions. More info

  • Uranium Finance Crypto Hacker Convicted of $53M Theft: A federal court found the individual behind the Uranium Finance smart contract exploit guilty of grand larceny and computer tampering following advanced multi-agency blockchain tracing. More info


⬅ Back to Archive

This post is licensed under CC BY 4.0 by the author.