DEV Community

NetSecOpsIO
NetSecOpsIO

Posted on Originally published at cyber.netsecops.io

Daily Cybersecurity Intelligence - September 9, 2026

Daily cybersecurity intelligence digest from CyberNetSec.io - September 9, 2026


📊 9 threat intelligence reports covering vulnerabilities, exploits, threat actors, and security advisories.


1. Microsoft September 2026 Patch Tuesday Fixes 974 CVEs

Microsoft has released its largest-ever security update for September 2026, addressing a record 974 vulnerabilities across its product portfolio. The update includes patches for 113 critical flaws and two zero-day vulnerabilities, CVE-2026-81963 and CVE-2026-85880, which are confirmed to be actively exploited in the wild. Both zero-days are privilege escalation flaws that allow attackers to gain SYSTEM-level access and have been added to CISA's KEV catalog. The release also contains fixes for numerous wormable remote code execution vulnerabilities, putting immense pressure on security teams to prioritize and deploy patches.

📖 Read full report →


2. CISA Adds Four Exploited Flaws to KEV Catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, indicating they are under active attack. The list includes two privilege escalation zero-days in Microsoft Windows (CVE-2026-81963, CVE-2026-85880), a critical RCE flaw in Adobe Commerce/Magento (CVE-2026-75650), and an RCE vulnerability in N-able N-central (CVE-2026-86218). Federal agencies are mandated to patch these flaws by September 22, 2026.

📖 Read full report →


3. US Warns of Chinese AI Model Theft Campaigns

The NSA, CISA, and FBI have issued a joint advisory accusing six China-based AI companies of conducting industrial-scale campaigns to steal intellectual property from leading U.S. AI models. The firms, including DeepSeek and Moonshot AI, allegedly use a technique called 'knowledge distillation' to query U.S. models like GPT and Gemini billions of times, effectively training their own models on the proprietary outputs. The agencies state this activity violates terms of service and is likely conducted with the awareness of the Chinese government.

📖 Read full report →


4. LHC Group Data Breach Exposes 162k Patient Records

LHC Group, a national home healthcare provider and a subsidiary of UnitedHealth Group's Optum, has disclosed a data breach affecting 162,578 individuals. The incident occurred in April 2026 after an employee's credentials were stolen in a voice phishing (vishing) attack. The threat actor used the compromised account to access a third-party vendor's platform, exfiltrating a vast amount of sensitive patient data, including Social Security numbers and protected health information (PHI).

📖 Read full report →


5. ShinyHunters Extorts Healthcare Org for $55M

The data extortion group ShinyHunters has claimed a massive breach of a healthcare organization, allegedly exfiltrating over 200 million records and demanding a $55 million ransom. The attack chain involved vishing to steal employee credentials, compromising Okta single sign-on (SSO), and then pivoting to Salesforce and Snowflake cloud environments to steal over a terabyte of data. The incident is part of a broader campaign by ShinyHunters targeting the healthcare sector with social engineering and MFA bypass tactics.

📖 Read full report →


6. Clop Ransomware Targets PTC Windchill Flaw

The Clop ransomware group is actively exploiting a critical remote code execution vulnerability (CVE-2026-12569) in PTC's Windchill and FlexPLM product lifecycle management (PLM) platforms. In a campaign reminiscent of its MOVEit attacks, Clop is breaching internet-facing PLM systems, deploying web shells, and exfiltrating large volumes of sensitive intellectual property and engineering data. The group has already named over 40 victims, including major corporations like Shell and Philips, on its data leak site.

📖 Read full report →


7. CISA Warns of CareCam Pro IP Camera Flaw

CISA has issued an Industrial Control Systems (ICS) advisory for a hard-coded credential vulnerability (CVE-2026-85083) in CareCam Pro IP cameras. The flaw, found in the ANJIA AJL33PC0801 model, could allow an attacker with physical access to the device to gain privileged access to the bootloader. This would enable them to take full control of the camera, modify firmware, and intercept video feeds. The vendor has not responded to CISA's coordination attempts.

📖 Read full report →


8. INC_RANSOM Hits NY Healthcare Provider

The INC_RANSOM ransomware group has listed Community Wellness Partners, a New York-based non-profit healthcare provider, as a victim on its data leak site. The incident, posted on September 7, 2026, continues the trend of ransomware gangs targeting the healthcare sector. While details are scarce, INC_RANSOM operates a double-extortion model, meaning they likely exfiltrated sensitive patient and employee data and are threatening to publish it if a ransom is not paid.

📖 Read full report →


9. CL-CRI-1171 Pay-Per-Install Network Analysis

A Unit 42 investigation has uncovered a massive cybercrime operation, tracked as CL-CRI-1171, that has been active for at least two years. The group operates a pay-per-install (PPI) marketplace, using YouTube gaming channels and search engine optimization (SEO) poisoning to lure victims into downloading a custom malware loader. This loader has been observed delivering a variety of payloads, including three recently analyzed strains: the newly dubbed Insomnia RAT, and the previously unreported ARKTunnel and Docro Hijacker. The campaign's success lies in its use of generic, disposable infrastructure that evades initial scrutiny, allowing multiple, unrelated threats to be deployed on a single compromised endpoint in enterprise and government environments.

📖 Read full report →


📌 Subscribe to daily updates at CyberNetSec.io

All reports include detailed analysis, IOCs, mitigation strategies, and references.

Top comments (0)