K Kyro9 News

Cybersecurity Briefing — September 24, 2026

The day's most significant cyber-security stories, curated from 50+ sources.

WeLiveSecurity (ESET) Threat Intelligence 15d ago
Safe word: What is it and why do you need one?
AI scams are now hyper-realistic. But there’s one simple way to see through them.
Also covered by Qualys Blog, Graham Cluley
WeLiveSecurity (ESET) Threat Intelligence 24d ago
This month in security with Tony Anscombe – August 2026 edition
Details about the Hugging Face hack, critical infrastructure under attack, a spoofed in-flight Wi-Fi network, and more of this month's cybersecurity news
Also covered by AWS Security Blog, Red Canary
Unit 42 (Palo Alto) Threat Intelligence 30d ago
The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution
Explore Unit 42 research on AI-enabled malware. Learn how existing behavioral detection and endpoint analytics stop AI-authored code before execution. The post The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic…
Also covered by Check Point Research, Elastic Security Labs
Google Project Zero Vulnerabilities 210d ago
A Deep Dive into the GetProcessHandleFromHwnd API
In my previous blog post I mentioned the GetProcessHandleFromHwnd API. This was an API I didn’t know existed until I found a publicly disclosed UAC bypass using the Quick Assist UI Access application. This API looked interesting so I…
Also covered by AWS Security Blog, Bitdefender Labs
SANS Internet Storm Center Threat Intelligence 6h ago
ISC Stormcast For Thursday, September 24th, 2026 https://isc.sans.edu/podcastdetail/10108, (Thu, Sep 24th)
Also covered by Rapid7 Blog
BleepingComputer News 12h ago
New RemControl Android banking malware targets users in Europe and Canada
A new Android malware-as-a-service (MaaS) platform called RemControl is targeting users through malvertising campaigns that impersonate the TVTap IPTV application. [...]
Also covered by Help Net Security
BleepingComputer News 14h ago
Check Point warns of hackers exploiting Security Gateway VPN RCE flaw
Cybersecurity company Check Point has confirmed active exploitation of CVE-2026-85102, a pre-authentication remote code execution (RCE) vulnerability in the VPN certificate-handling functionality of its Security Gateway product. [...]
Also covered by Canadian Centre for Cyber Security
BleepingComputer News 15h ago
Hackers start exploiting critical WordPress flaw for code execution
Threat actors have moved from probing WordPress sites vulnerable to CVE-2026-87902 to exploiting the flaw to write files to disk that execute shell commands when accessed. [...]
Also covered by The Hacker News
The Record (Recorded Future) Threat Intelligence 18h ago
Ryuk ransomware operator gets 2-year sentence after extorting victims for $1.2 million
An Armenian national and member of the Ryuk ransomware gang was sentenced to two years in federal prison for his role in launching attacks.
Also covered by CyberScoop
BleepingComputer News 21h ago
Arista patches actively exploited VeloCloud Orchestrator zero-day
Arista Networks has released security patches for a zero-day flaw that is being actively exploited and affects VeloCloud Orchestrator (VCO) On-Prem deployments. [...]
Also covered by CISA Known Exploited Vulnerabilities
The Hacker News News 1d ago
F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers
Attackers are exploiting a critical flaw in F5 BIG-IP Access Policy Manager (APM) that lets them run code on a BIG-IP system without logging in, F5 says. The flaw, CVE-2026-94127, affects only systems in which APM serves as an OAuth…
Also covered by Rapid7 Blog
BleepingComputer News 1d ago
Ryuk ransomware member sentenced to 24 months in prison
An Armenian man was sentenced to 24 months in prison and 3 years of supervised release for hacking U.S. companies and encrypting their systems in Ryuk ransomware attacks. [...]
Also covered by SecurityWeek
Zero Day Initiative Vulnerabilities 1d ago
ZDI-26-742: Foxit PDF Reader FoxitUpdater Race Condition Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Foxit PDF Reader. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this…
Also covered by Elastic Security Labs
Canadian Centre for Cyber Security Advisories 1d ago
AL26-022 - Vulnerability impacting F5 BIG-IP Access Policy Manager (APM) – CVE-2026-94127
Also covered by CISA Known Exploited Vulnerabilities
CISA Known Exploited Vulnerabilities Threat Intelligence 2d ago
CVE-2026-93616 added to CISA KEV — Check Point Multiple Products
Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent contain a path traversal vulnerability that allows an unauthenticated attacker to upload and execute…
Also covered by CERT-EU
Check Point Research Threat Intelligence 2d ago
21st September – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 21st Setpember, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Japan’s Digital Agency, which operates the Government Solution Service used by multiple…
Also covered by Wordfence
Google Project Zero Vulnerabilities 3d ago
Windows Exploitation Techniques: Dangling COM Object Registrations
This short blog post is about abusing a privilege escalation bug that Microsoft recently fixed in Windows, CVE-2026-66804, that I and 14 others reported. This issue is an incomplete fix for CVE-2026-50343, a bug dubbed “Dark Elevator” by…
Also covered by Reddit r/netsec
CISA Known Exploited Vulnerabilities Threat Intelligence 6d ago
CVE-2025-39964 added to CISA KEV — Linux Kernel
Linux Kernel contains a race condition vulnerability which allows concurrent writes to the same AF_ALG socket causing data to be unpredictably interleaved and creating inconsistencies in the socket's internal state.
Also covered by Qualys Blog
Check Point Research Threat Intelligence 6d ago
AI Threat Landscape Digest: July–August 2026
The defining development of the period came not from attackers but from the AI labs themselves, whose models broke out of controlled evaluations and reached real systems. In the wild, the criminal and state use of AI continued to mature…
Also covered by Kaspersky Securelist
Kaspersky Securelist Threat Intelligence 6d ago
The Odyssey and Trojans again: MovieReaper attacks users in multiple countries through compromised torrents
Kaspersky experts have discovered a new MovieReaper campaign. The multi-stage Trojan spreads through movie torrents, such as The Odyssey, and uses the Solana blockchain to hide its C2 infrastructure.
Also covered by HackRead
Kyro9 — AI-native cloud securitySee what's actually exploitable in your cloud. Fix it fast. Self-hostable, no lock-in.
Explore the platform Book a live demo