Cybersecurity Newsfeed - 09/10/26
Daily cybersecurity news covering vulnerabilities, adversaries, trends, breaches, and other notable security developments.
Cybersecurity Newsfeed
📅 09/10/26
🛡️ Vulnerabilities
Cisco Nexus Switch Flaws Allow Complete Administrative Takeover: Cisco issued urgent advisories for critical vulnerabilities in its Nexus switch series running NX-OS software. Unauthenticated, remote attackers can execute arbitrary code with root privileges or trigger severe DoS conditions via specially crafted packets. More info
Critical Atlassian Vulnerability Exploited Hours After PoC: Threat actors rapidly integrated a published proof-of-concept exploit code into automated scanning tools to target unpatched Atlassian Confluence and Jira instances globally, permitting unauthenticated remote code execution. More info
“AgentCorruption” Vulnerability Threatens AWS AI Environments: Researchers revealed a critical flaw affecting AWS environments integrated with AI agents. Threat actors can bypass access controls, extract cloud credentials, and execute unauthorized commands via a single prompt injection attack. More info
Samsung Galaxy S26 Exploited Three More Times at Pwn2Own: Security researchers demonstrated zero-day input validation, privilege escalation, and remote code execution flaws affecting the baseband and core OS components of the Samsung Galaxy S26. More info
🎯 Adversaries
FBI Disrupts Chinese State-Sponsored Critical Infrastructure Breach: Federal law enforcement neutralized malicious infrastructure, custom malware, and compromised botnet nodes used by Chinese threat actors targeting US government, energy, and telecommunications networks. More info
Russian Spies Update MatchBoil Malware: Russian state-sponsored operatives deployed a facelifted variant of the MatchBoil malware family targeting diplomatic and government entities, featuring advanced anti-analysis and encrypted C2 communications. More info
FakeGit Campaign Resurfaces with 17,610 Weaponized Repositories: A massive malicious software campaign automated weaponized GitHub repository creation to distribute information stealers and remote access trojans targeting software developers. More info
PoeLLM Malware Targets Open-Source AI Infrastructure: A malware campaign named PoeLLM was discovered uploading malicious packages to GitHub targeting AI servers, harvesting API keys, cloud credentials, and model weights. More info
Sixteen Malicious Firefox Add-Ons Stole User Session Data: Researchers identified sixteen malicious Firefox extensions posing as legitimate browser tools that covertly injected JavaScript to log keystrokes and capture credentials for banking and cloud services. More info
Cisco Talos Uncovers UAT-11985 Corporate Cyber Espionage: Threat actor group UAT-11985 is targeting corporate networks using compromised credentials, custom backdoors, credential dumping, and log suppression techniques to evade detection. More info
Artex AI Pentesting Framework Weaponized for Data Exfiltration: Threat actors repurposed the open-source Artex AI penetration testing framework to map target networks, execute automated privilege escalations, and exfiltrate enterprise databases. More info
- Hunt.io Identifies New Brazetsu Banking Malware Infrastructure: Proactive telemetry and banner scanning revealed new Brazetsu C2 servers and distribution endpoints targeting financial institutions months before public vendor disclosure. More info
📈 Trends
Global Cyberattacks Surge 48% Driven by Ransomware and Phishing: Check Point Research revealed a significant spike in global cyberattacks targeting education, healthcare, and government sectors, fueled by AI-driven lures and double-extortion tactics. More info
Ransomware Affiliates Target Identity Providers and MFA: Attackers are increasingly bypassing perimeter controls by exploiting stolen session tokens, misconfigured authentication frameworks, and conducting MFA fatigue attacks. More info
Accumulating OAuth Permissions Create Persistent Risks: Security experts warned of unreviewed third-party OAuth integrations being leveraged by threat actors to retain persistent, passwordless access to cloud tenants like Microsoft 365 and Google Workspace. More info
Low-Cost Android Phones Shipped Pre-Infected with Proxy Malware: A supply chain compromise resulted in budget Android smartphones shipping with pre-installed firmware malware that converts devices into residential proxy nodes for ad fraud and credential stuffing. More info
Microsoft Teams to Add Native Deepfake Detection Features: Microsoft announced integrated AI capabilities for Teams to detect synthetic audio, voice cloning, and deepfake video streams during live enterprise calls in real time. More info
GitHub Integrates ModernBERT AI into Secret Scanning: GitHub expanded Push Protection using ModernBERT machine learning models to detect exposed API keys, private tokens, and credentials in code prior to public commit. More info
💥 Breaches & Leaks
Ransomware Attack Forces IDCF Japan Cloud Offline: A severe ransomware incident impacted Japan’s Industrial Decisions Corporation Infrastructure cloud, forcing system isolation and service outages across enterprise and public sector clients. More info
Japan Experiences Sharp Surge in Web-Based Data Leaks: Misconfigured cloud storage, unpatched web application vulnerabilities, and credential stuffing led to a dramatic spike in corporate and government data exposures across Japan. More info
Ransomware and Phishing Force Small Construction Firm out of Business: A firm ceased operations after a catastrophic ransomware attack encrypted operational databases and backup drives following unpatched server exploitation and MFA-bypassing phishing. More info
⚖️ Legal & Enforcement
Empire Dark Web Market Operator Sentenced to 40 Years: The administrator of Empire Market received a 40-year federal prison sentence for facilitating hundreds of millions of dollars in illicit drug, weapon, and cybercrime transactions. More info
Uranium Finance Crypto Hacker Convicted of $53M Theft: A federal court found the individual behind the Uranium Finance smart contract exploit guilty of grand larceny and computer tampering following advanced multi-agency blockchain tracing. More info
