K Kyro9 News

Cybersecurity Briefing — September 22, 2026

The day's most significant cyber-security stories, curated from 50+ sources.

The Record (Recorded Future) Threat Intelligence 14h ago
EU data regulator fines Google more than $460 million for location data violations
Ireland’s Data Protection Commission will fine Google more than €403 million ($462 million) over the tech giant’s processing of location data, concluding an inquiry into the company that began in early 2020.
Also covered by The Hacker News, BleepingComputer, SecurityWeek
BleepingComputer News 13h ago
CISA alerts of active exploitation of three Linux kernel flaws
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning that hackers are exploiting three Linux kernel vulnerabilities, one of them rated critical. [...]
Also covered by CISA Known Exploited Vulnerabilities, SC Media
JPCERT/CC (Japan) Advisories 13d ago
Security Alert: Microsoft Releases September 2026 Security Updates
Also covered by Rapid7 Blog, Qualys Blog
Unit 42 (Palo Alto) Threat Intelligence 28d ago
The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution
Explore Unit 42 research on AI-enabled malware. Learn how existing behavioral detection and endpoint analytics stop AI-authored code before execution. The post The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic…
Also covered by Check Point Research, Elastic Security Labs
Google Project Zero Vulnerabilities 208d ago
A Deep Dive into the GetProcessHandleFromHwnd API
In my previous blog post I mentioned the GetProcessHandleFromHwnd API. This was an API I didn’t know existed until I found a publicly disclosed UAC bypass using the Quick Assist UI Access application. This API looked interesting so I…
Also covered by AWS Security Blog, Bitdefender Labs
Check Point Research Threat Intelligence 10h ago
21st September – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 21st Setpember, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Japan’s Digital Agency, which operates the Government Solution Service used by multiple…
Also covered by Wordfence
BleepingComputer News 20h ago
FBI's CJIS v6.1: What Security Teams Need to Know.
The FBI's CJIS Security Policy v6.1 strengthens requirements around encryption and vulnerability scanning while continuing the shift toward more continuous security assessment. Specops explains what changed and how agencies can address…
Also covered by WeLiveSecurity (ESET)
The Record (Recorded Future) Threat Intelligence 20h ago
ShinyHunters cybercrime gang takes over Cl0p ransomware site, demands extortion payment
The ShinyHunters extortion group hijacked the dark web leak site of the prolific Cl0p ransomware gang, according to material posted on the site over the weekend.
Also covered by Malwarebytes Labs
Google Project Zero Vulnerabilities 1d ago
Windows Exploitation Techniques: Dangling COM Object Registrations
This short blog post is about abusing a privilege escalation bug that Microsoft recently fixed in Windows, CVE-2026-66804, that I and 14 others reported. This issue is an incomplete fix for CVE-2026-50343, a bug dubbed “Dark Elevator” by…
Also covered by Reddit r/netsec
Zero Day Initiative Vulnerabilities 4d ago
ZDI-26-718: Cisco Identity Services Engine MnTRESTLivelogService XML External Entity Processing Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Cisco Identity Services Engine. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.9.…
Also covered by CISA Known Exploited Vulnerabilities
Check Point Research Threat Intelligence 4d ago
AI Threat Landscape Digest: July–August 2026
The defining development of the period came not from attackers but from the AI labs themselves, whose models broke out of controlled evaluations and reached real systems. In the wild, the criminal and state use of AI continued to mature…
Also covered by Kaspersky Securelist
Kaspersky Securelist Threat Intelligence 6d ago
NightEagle targets Russian companies
Kaspersky GERT experts have uncovered a new campaign by the NightEagle APT, featuring the GhostContainer backdoor and tools hosted on GitHub. The group is also exploiting vulnerabilities in Active Directory and RDP.
Also covered by Citizen Lab
Zero Day Initiative Vulnerabilities 6d ago
ZDI-26-711: NoMachine Redis Improper Authentication Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of NoMachine. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.…
Also covered by Elastic Security Labs
Zero Day Initiative Vulnerabilities 6d ago
ZDI-26-707: (0Day) MindsDB OpenBBtable Code Injection Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of MindsDB. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are…
Also covered by Wordfence
CISA Known Exploited Vulnerabilities Threat Intelligence 8d ago
CVE-2026-76461 added to CISA KEV — Cisco Secure Email Gateway
Cisco AsyncOS software for Cisco Secure Email Gateway (SEG) contains a SQL injection vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.
Also covered by Rapid7 Blog
Cisco Talos Threat Intelligence 12d ago
Active exploitation of Cisco Secure Firewall Management Center vulnerabilities
Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco’s Secure Firewall Management Center (FMC) Software.
Also covered by Infosecurity Magazine
CISA Known Exploited Vulnerabilities Threat Intelligence 13d ago
CVE-2026-19490 added to CISA KEV — Citrix NetScaler
Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability involving an alternate path or channel. When the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy,…
Also covered by Rapid7 Blog
Cisco Talos Threat Intelligence 13d ago
Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities
Microsoft has released its monthly security update for September 2026, which includes 973 vulnerabilities affecting a range of products, including 113 that Microsoft marked as "critical."
Also covered by CrowdStrike
WeLiveSecurity (ESET) Threat Intelligence 22d ago
This month in security with Tony Anscombe – August 2026 edition
Details about the Hugging Face hack, critical infrastructure under attack, a spoofed in-flight Wi-Fi network, and more of this month's cybersecurity news
Also covered by Red Canary
SentinelOne Research Threat Intelligence 26d ago
Edge Infrastructure Under Siege: What Two Independent Datasets Reveal About Who's Exploiting Your Perimeter
A new joint study by Tenable and SentinelOne reveals how state and criminal groups converge on the same vulnerable edge infrastructure.
Also covered by Tenable Blog
Kyro9 — AI-native cloud securitySee what's actually exploitable in your cloud. Fix it fast. Self-hostable, no lock-in.
Explore the platform Book a live demo