DEV Community

NetSecOpsIO
NetSecOpsIO

Posted on Originally published at cyber.netsecops.io

Daily Cybersecurity Intelligence - September 23, 2026

Daily cybersecurity intelligence digest from CyberNetSec.io - September 23, 2026


📊 8 threat intelligence reports covering vulnerabilities, exploits, threat actors, and security advisories.


1. Check Point Patches Two Critical Zero-Days Exploited in the Wild

Check Point has released urgent patches for two critical, actively exploited zero-day vulnerabilities. The first, CVE-2026-93616, is a path traversal flaw in management servers allowing remote code execution. The second, CVE-2026-85102, is an authentication bypass in VPN gateways. Both have been added to CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating widespread exploitation and requiring immediate attention from defenders. Attacks against the management server flaw have been observed since July 2026.

📖 Read full report →


2. F5 Patches Critical BIG-IP RCE Flaw Added to CISA KEV Catalog

F5 has released an emergency patch for a critical unauthenticated RCE vulnerability, CVE-2026-94127 (CVSS 9.8), in its BIG-IP Access Policy Manager (APM). The flaw, a heap-based buffer overflow, is being actively exploited in the wild. It affects systems configured with a specific combination of an APM access policy and an OAuth Authorization Server profile. CISA has added the vulnerability to its KEV catalog and mandated federal agencies patch by September 25, 2026. Over 14,700 instances are potentially vulnerable.

📖 Read full report →


3. BigCommerce Merchants Suffer Data Breach in Ribon App Supply Chain Attack

A supply chain attack has impacted hundreds of merchants on the BigCommerce e-commerce platform. Threat actors compromised an API key for the third-party 'Ribon' application, using it between September 13-17, 2026, to exfiltrate customer data. Exposed information includes names, emails, phone numbers, and shipping addresses. The incident highlights the significant security risks associated with third-party application integrations in SaaS ecosystems.

📖 Read full report →


4. Cisco Talos Unveils CLOSEDQUORUM, an Autonomous AI-Driven Malware

Cisco Talos has discovered a groundbreaking Windows malware implant named 'CLOSEDQUORUM' that uses a panel of four commercial Large Language Models (LLMs) for its command-and-control (C2). The Go-based binary operates autonomously, querying models from Google, Mistral, and others to decide its next action, such as stealing credentials or crypto wallets. While the analyzed sample appears to be a kit not yet deployed, it represents a significant architectural shift towards attack automation.

📖 Read full report →


5. NPM Package 'indexed-btree' Uses Runtime Evasion to Deliver Malware

A malicious npm package, 'indexed-btree,' was downloaded nearly two million times per week before its removal. The package evaded security scanners by hiding its malicious loader in a runtime function instead of common install scripts. Once triggered by an application, it fingerprinted the host, exfiltrated data via Slack and Telegram, and used the Ethereum blockchain for its second-stage C2. The campaign earned its creator over €230,000, highlighting a sophisticated evolution in software supply chain attacks.

📖 Read full report →


6. Water Hydra's DarkMe RAT Campaign Pivots to Phishing Attacks

The financially motivated APT group Water Hydra (aka EvilNum) has shifted tactics in its distribution of the DarkMe Remote Access Trojan (RAT). Previously known for using zero-day exploits, a new campaign observed by Huntress relies on simple phishing emails with malicious .pif file attachments. The malware uses a multi-stage loader, COM registration for persistence, and process hollowing to evade detection while stealing cryptocurrency wallets and other system data. This change indicates a move towards lower-cost, higher-volume attacks.

📖 Read full report →


7. August 2026 Ransomware Attacks Hit Yearly High, Qilin Group Dominates

Ransomware attacks surged to a new 2026 record in August, with 1,073 victims reported globally, a 12% increase from July, according to NCC Group. The industrial sector was the most frequent target, accounting for 31% of all incidents. North America remained the most affected region. The Qilin ransomware group emerged as the most prolific threat actor for the month, responsible for 15% of attributable attacks, overtaking 'The Gentlemen' group.

📖 Read full report →


8. Barracuda, PDI Launch Platforms to Govern Enterprise 'Shadow AI' Use

In response to the rapid and often ungoverned enterprise adoption of generative AI, several cybersecurity vendors have launched new security platforms. Companies like Barracuda and PDI Technologies have released tools designed to discover and manage 'shadow AI,' control the flow of sensitive data into external Large Language Models (LLMs), and help organizations enforce responsible AI use policies. These solutions aim to provide visibility into the thousands of AI tools being used by employees and mitigate risks like data leakage and prompt injection.

📖 Read full report →


📌 Subscribe to daily updates at CyberNetSec.io

All reports include detailed analysis, IOCs, mitigation strategies, and references.

Top comments (0)