Daily cybersecurity intelligence digest from CyberNetSec.io - September 23, 2026
📊 8 threat intelligence reports covering vulnerabilities, exploits, threat actors, and security advisories.
1. Check Point Patches Two Critical Zero-Days Exploited in the Wild
Check Point has released urgent patches for two critical, actively exploited zero-day vulnerabilities. The first, CVE-2026-93616, is a path traversal flaw in management servers allowing remote code execution. The second, CVE-2026-85102, is an authentication bypass in VPN gateways. Both have been added to CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating widespread exploitation and requiring immediate attention from defenders. Attacks against the management server flaw have been observed since July 2026.
2. F5 Patches Critical BIG-IP RCE Flaw Added to CISA KEV Catalog
F5 has released an emergency patch for a critical unauthenticated RCE vulnerability, CVE-2026-94127 (CVSS 9.8), in its BIG-IP Access Policy Manager (APM). The flaw, a heap-based buffer overflow, is being actively exploited in the wild. It affects systems configured with a specific combination of an APM access policy and an OAuth Authorization Server profile. CISA has added the vulnerability to its KEV catalog and mandated federal agencies patch by September 25, 2026. Over 14,700 instances are potentially vulnerable.
3. BigCommerce Merchants Suffer Data Breach in Ribon App Supply Chain Attack
A supply chain attack has impacted hundreds of merchants on the BigCommerce e-commerce platform. Threat actors compromised an API key for the third-party 'Ribon' application, using it between September 13-17, 2026, to exfiltrate customer data. Exposed information includes names, emails, phone numbers, and shipping addresses. The incident highlights the significant security risks associated with third-party application integrations in SaaS ecosystems.
4. Cisco Talos Unveils CLOSEDQUORUM, an Autonomous AI-Driven Malware
Cisco Talos has discovered a groundbreaking Windows malware implant named 'CLOSEDQUORUM' that uses a panel of four commercial Large Language Models (LLMs) for its command-and-control (C2). The Go-based binary operates autonomously, querying models from Google, Mistral, and others to decide its next action, such as stealing credentials or crypto wallets. While the analyzed sample appears to be a kit not yet deployed, it represents a significant architectural shift towards attack automation.
5. NPM Package 'indexed-btree' Uses Runtime Evasion to Deliver Malware
A malicious npm package, 'indexed-btree,' was downloaded nearly two million times per week before its removal. The package evaded security scanners by hiding its malicious loader in a runtime function instead of common install scripts. Once triggered by an application, it fingerprinted the host, exfiltrated data via Slack and Telegram, and used the Ethereum blockchain for its second-stage C2. The campaign earned its creator over €230,000, highlighting a sophisticated evolution in software supply chain attacks.
6. Water Hydra's DarkMe RAT Campaign Pivots to Phishing Attacks
The financially motivated APT group Water Hydra (aka EvilNum) has shifted tactics in its distribution of the DarkMe Remote Access Trojan (RAT). Previously known for using zero-day exploits, a new campaign observed by Huntress relies on simple phishing emails with malicious .pif file attachments. The malware uses a multi-stage loader, COM registration for persistence, and process hollowing to evade detection while stealing cryptocurrency wallets and other system data. This change indicates a move towards lower-cost, higher-volume attacks.
7. August 2026 Ransomware Attacks Hit Yearly High, Qilin Group Dominates
Ransomware attacks surged to a new 2026 record in August, with 1,073 victims reported globally, a 12% increase from July, according to NCC Group. The industrial sector was the most frequent target, accounting for 31% of all incidents. North America remained the most affected region. The Qilin ransomware group emerged as the most prolific threat actor for the month, responsible for 15% of attributable attacks, overtaking 'The Gentlemen' group.
8. Barracuda, PDI Launch Platforms to Govern Enterprise 'Shadow AI' Use
In response to the rapid and often ungoverned enterprise adoption of generative AI, several cybersecurity vendors have launched new security platforms. Companies like Barracuda and PDI Technologies have released tools designed to discover and manage 'shadow AI,' control the flow of sensitive data into external Large Language Models (LLMs), and help organizations enforce responsible AI use policies. These solutions aim to provide visibility into the thousands of AI tools being used by employees and mitigate risks like data leakage and prompt injection.
📌 Subscribe to daily updates at CyberNetSec.io
All reports include detailed analysis, IOCs, mitigation strategies, and references.
Top comments (0)