Daily cybersecurity intelligence digest from CyberNetSec.io - September 24, 2026
📊 8 threat intelligence reports covering vulnerabilities, exploits, threat actors, and security advisories.
1. CISA & FBI Urge Tighter Security for Third-Party ICS Integrators
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the FBI have issued a joint advisory highlighting the significant cyber risks posed by third-party Industrial Control System (ICS) integrators. The guidance urges critical infrastructure operators to enforce the principle of least privilege, enhance contractual security requirements, and improve monitoring of remote access to protect sensitive operational technology (OT) environments from supply chain attacks.
2. Google Hit with €403 Million Fine for GDPR Location Data Breaches
Ireland's Data Protection Commission (DPC) has imposed a €403 million fine on Google for violations of the EU's General Data Protection Regulation (GDPR). The penalty, one of the largest of its kind, follows a six-year inquiry into Google's processing of user location data between 2018 and 2020. The DPC found the company's practices lacked lawfulness, fairness, and transparency, particularly concerning its 'Web & App Activity' and 'Location History' features.
3. MGM Resorts Reports System Shutdown Due to Cyberattack
MGM Resorts International has proactively shut down some of its computer systems to contain a cyberattack detected on September 23, 2026. The move has caused operational disruptions across its properties. Details regarding the nature of the attack, the threat actor involved, and whether data was compromised have not yet been disclosed as the investigation is ongoing.
4. Ransomware Attacks Hit Record High, NCC Group Reports
According to a new report from NCC Group, global ransomware attacks surged to a 2026 record in August, victimizing 1,073 organizations. This marks a 12% increase from July and a significant year-over-year rise. The industrial sector was the most frequent target, and the Qilin and The Gentlemen ransomware groups were the most prolific actors during the month.
5. Thales Report: AI and Cloud Risks for Manufacturing Sector
The 2026 Thales Data Threat Report for the manufacturing sector reveals widespread concern over AI-driven security threats, with 67% of executives citing the rapid pace of AI change as their top risk. The report also highlights alarming gaps in cloud security, with only 31% of organizations having full visibility of their data's location and very low rates of encryption for sensitive data stored in the cloud.
6. GAO Finds FAA Lacks Real-Time Aviation Cyber Threat Monitoring
A U.S. Government Accountability Office (GAO) report has identified critical cybersecurity weaknesses at the Federal Aviation Administration (FAA). The report finds the FAA has failed to complete required risk assessments and lacks a real-time capability to monitor for threats like spoofing and jamming against the National Airspace System (NAS). This leaves key aircraft communication systems vulnerable to disruption.
7. Infotree Global Solutions Data Breach Under Investigation
The law firm Edelson Lechtzin LLP is investigating a data breach at staffing and payroll company Infotree Global Solutions. The breach occurred when an employee accidentally emailed documents containing sensitive personal information, including names and Social Security numbers, to an unauthorized individual. The company has notified affected parties and offered identity protection services.
8. ShinyHunters Claims FBI Hack via PeopleSoft Zero-Day
The notorious extortion group ShinyHunters has claimed responsibility for a breach of the Federal Bureau of Investigation (FBI). In a post on September 23, 2026, the group alleged it exploited a zero-day vulnerability in PeopleSoft software to steal sensitive data on agents and job applicants. The attack was allegedly in retaliation for a recent FBI report on the group. The FBI has not confirmed the claim.
📌 Subscribe to daily updates at CyberNetSec.io
All reports include detailed analysis, IOCs, mitigation strategies, and references.
Top comments (0)