DEV Community

NetSecOpsIO
NetSecOpsIO

Posted on Originally published at cyber.netsecops.io

Daily Cybersecurity Intelligence - September 14, 2026

Daily cybersecurity intelligence digest from CyberNetSec.io - September 14, 2026


📊 9 threat intelligence reports covering vulnerabilities, exploits, threat actors, and security advisories.


1. GitLab Critical Vulnerability CVE-2026-85706 Exploited

GitLab has issued emergency patches for a critical path traversal vulnerability, CVE-2026-85706, which has a perfect 10.0 CVSS score. The flaw allows unauthenticated attackers to read arbitrary files on affected servers. Following its disclosure, security researchers and CISA have confirmed widespread, active exploitation in the wild, leading to its addition to the Known Exploited Vulnerabilities (KEV) catalog. The vulnerability affects GitLab CE/EE versions 18.7 through 19.3.1, and administrators are urged to update immediately.

📖 Read full report →


2. Microsoft September 2026 Patch Tuesday

Microsoft has released its largest-ever security update for September 2026 Patch Tuesday, addressing a record 974 vulnerabilities. The massive release includes patches for two actively exploited zero-day privilege escalation flaws, CVE-2026-81963 and CVE-2026-85880. Additionally, the update fixes 113 critical vulnerabilities, with over 20 being unauthenticated Remote Code Execution (RCE) bugs in core services like Windows DNS, DHCP, and Message Queuing, posing a severe risk to enterprise infrastructure.

📖 Read full report →


3. Passkey Phishing Hijacks Microsoft Cloud Accounts

A sophisticated social engineering campaign is targeting Microsoft cloud service users with passkey-themed phishing lures. Attackers contact employees on their personal phones, impersonating IT support and creating a false sense of urgency to 'update' their passkey, MFA, or SSO settings. Victims are directed to a convincing phishing site that harvests their credentials, leading to account takeover and data exfiltration. The campaign highlights a trend of attackers abusing trusted communication channels and identity-related themes to bypass user vigilance.

📖 Read full report →


4. CISA Adds 5 Exploited Flaws to KEV Catalog

The U.S. CISA has added five actively exploited vulnerabilities to its KEV catalog, impacting products from JFrog, ConnectWise, and MikroTik. The flaws include two in JFrog Artifactory (CVE-2026-42016, CVE-2026-42018), one in ConnectWise ScreenConnect (CVE-2026-84869), and two in MikroTik RouterOS (CVE-2026-67277, CVE-2026-86060). These vulnerabilities enable privilege escalation, remote code execution, and data leakage, prompting mandatory patching deadlines for U.S. federal agencies.

📖 Read full report →


5. EU CRA Single Reporting Platform Now Live

The EU's cybersecurity agency, ENISA, has launched the Cyber Resilience Act (CRA) Single Reporting Platform. Effective September 11, 2026, manufacturers of products with digital elements sold in the EU must use this portal to report actively exploited vulnerabilities and severe incidents. The regulation imposes strict deadlines, requiring an initial warning within 24 hours of awareness, a detailed notification within 72 hours, and a final report within 14 days of a patch being available. The move aims to streamline reporting and enhance resilience across the EU's Digital Single Market.

📖 Read full report →


6. Global Ransomware Attacks Surge to Record High

Global ransomware attacks reached a new peak in August 2026, with a record 997 incidents reported, a 23% increase from July. According to data from Comparitech, this averages to 32 attacks per day. The utility sector was hit particularly hard, with attacks doubling, while the healthcare sector saw a 30% rise. The Qilin and The Gentlemen ransomware gangs were the most prolific, collectively responsible for over a quarter of all attacks. The Clop group also resurfaced, linking attacks to a vulnerability in PTC Windchill.

📖 Read full report →


7. Mathspace Data Breach Hits Over 1 Million Users

The Australian education platform Mathspace has disclosed a data breach affecting over one million users. Attackers gained access to an internal reporting database by exploiting CVE-2026-72898, a known SQL injection vulnerability in a self-hosted instance of the open-source business intelligence tool, Metabase. The compromised data includes user names, email addresses, and location information. The company stated that more sensitive data like passwords and academic records were not impacted.

📖 Read full report →


8. Hacking Cat Group Uses Wiper Malware on Russia

The pro-Ukrainian hacktivist group 'Hacking Cat' has reportedly escalated its cyber operations against Russian organizations by deploying custom-built malware, including destructive data wipers. The group's stated goal is to disrupt Russian military logistics. This shift from simple disruption or data leaks to the use of destructive malware marks a significant tactical evolution. The incident also highlights the challenge of attribution, as researchers note an overlap in tools used by Hacking Cat and other pro-Ukrainian groups, and the group itself has disputed some public attributions.

📖 Read full report →


9. Behavioral Clustering Model Maps Cloud Identity Roles from Audit Logs

Palo Alto Networks' Unit 42 has published research on a new behavioral clustering model that uses unsupervised machine learning to analyze cloud audit logs. By examining over 40,000 identities in AWS environments, the model, which leverages UMAP and HDBSCAN algorithms, successfully maps entities to their functional roles, such as administrators or DevOps tools. A key outcome of this research is the ability to translate these complex behavioral patterns into lightweight, portable SQL queries. This allows organizations to implement continuous, scalable threat detection to identify anomalous activities and masquerading threats without the overhead of a persistent machine learning pipeline.

📖 Read full report →


📌 Subscribe to daily updates at CyberNetSec.io

All reports include detailed analysis, IOCs, mitigation strategies, and references.

Top comments (0)