K Kyro9 News

Cybersecurity Briefing — September 29, 2026

The day's most significant cyber-security stories, curated from 50+ sources.

SANS Internet Storm Center Threat Intelligence 20h ago
ISC Stormcast For Tuesday, September 29th, 2026 https://isc.sans.edu/podcastdetail/10114, (Tue, Sep 29th)
Also covered by Cisco Talos, CrowdStrike, Rapid7 Blog, Tenable Blog
CERT-EU Advisories 2d ago
2026-014: Critical Vulnerabilities in Citrix NetScaler ADC and Gateway
On 27 September 2026, Citrix published a security bulletin addressing 8 vulnerabilities affecting customer-managed Citrix NetScaler ADC and Citrix NetScaler Gateway, among which 2 critical unauthenticated Remote Code Execution (RCE)…
Also covered by Canadian Centre for Cyber Security, Rapid7 Blog, CSO Online, Tenable Blog
The Hacker News News 13h ago
Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation
Dutch authorities have confirmed that they arrested a 24-year-old man from Amsterdam in connection with the ShinyHunters group. "It is true that this month a 24-year-old man from Amsterdam was arrested in an investigation into the hacker…
Also covered by BleepingComputer, Krebs on Security, TechCrunch (Security)
The Hacker News News 17h ago
OpenAI Pauses Tool Use After Agent Bypasses Internet Controls to Reach External Chatbot
OpenAI said it has made the decision to pause training of its most powerful models after one of its agents during reinforcement learning (RL) training contacted an external chatbot by exploiting a loophole in its internet-access…
Also covered by CSO Online, Malwarebytes Labs
WeLiveSecurity (ESET) Threat Intelligence 20d ago
Safe word: What is it and why do you need one?
AI scams are now hyper-realistic. But there’s one simple way to see through them.
Also covered by Qualys Blog, Graham Cluley
Unit 42 (Palo Alto) Threat Intelligence 35d ago
The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution
Explore Unit 42 research on AI-enabled malware. Learn how existing behavioral detection and endpoint analytics stop AI-authored code before execution. The post The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic…
Also covered by Check Point Research, Elastic Security Labs
Google Project Zero Vulnerabilities 215d ago
A Deep Dive into the GetProcessHandleFromHwnd API
In my previous blog post I mentioned the GetProcessHandleFromHwnd API. This was an API I didn’t know existed until I found a publicly disclosed UAC bypass using the Quick Assist UI Access application. This API looked interesting so I…
Also covered by AWS Security Blog, Bitdefender Labs
The Record (Recorded Future) Threat Intelligence 1h ago
US Air Force members given over 6 years in prison for cyber theft of more than $2 million
According to court documents, both men pleaded guilty to wire fraud, identity theft and access device fraud charges in June.
Also covered by BleepingComputer
BleepingComputer News 1h ago
Custom ChatGPTs push ClickFix attacks to deploy RAT malware
Custom variants of OpenAI's ChatGPT promoted in sponsored Google results are directing unsuspecting users to malicious sites that use ClickFix attacks to deliver malware. [...]
Also covered by SecurityWeek
The Record (Recorded Future) Threat Intelligence 2h ago
OpenAI apologizes for agents breaching Australian government websites without authorization
The artificial intelligence giant acknowledged it botched its response to the incidents and should have done more to promptly notify and work with the Australian government in the days after it discovered the breaches.
Also covered by TechCrunch (Security)
CISA ICS Advisories Advisories 10h ago
MikroTik RouterOS
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to achieve remote code execution or cause a denial of service. The following versions of MikroTik RouterOS are affected: RouterOS <7.24…
Also covered by CISA Known Exploited Vulnerabilities
BleepingComputer News 14h ago
Apple patches CoreGraphics zero-day flaw exploited in attacks
Apple released security updates to fix a zero-day vulnerability exploited in "extremely sophisticated" targeted attacks on iOS devices. [...]
Also covered by The Hacker News
The Hacker News News 1d ago
Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks
Hackers have used a malware family called NeedyMantis to maintain long-term access to networks they had already breached, Microsoft said in a technical analysis. The malware has been seen in a small number of targeted intrusions at…
Also covered by Dark Reading
Check Point Research Threat Intelligence 1d ago
28th September – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 28th September, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES The FBI has confirmed unauthorized activity affecting FBIjobs.gov after the…
Also covered by Wordfence
CISA Known Exploited Vulnerabilities Threat Intelligence 2d ago
CVE-2026-88772 added to CISA KEV — Citrix NetScaler
Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for remote code execution or denial of service
Also covered by Reddit r/netsec
CISA Known Exploited Vulnerabilities Threat Intelligence 5d ago
CVE-2026-71362 added to CISA KEV — Adobe Commerce and Magento
Adobe Commerce and Magento contains an incorrect authorization vulnerability that could allow an attacker to leverage this vulnerability to gain elevated access to sensitive resources without any user interaction.
Also covered by Tenable Blog
Zero Day Initiative Vulnerabilities 6d ago
ZDI-26-742: Foxit PDF Reader FoxitUpdater Race Condition Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Foxit PDF Reader. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this…
Also covered by Elastic Security Labs
CISA Known Exploited Vulnerabilities Threat Intelligence 11d ago
CVE-2025-39964 added to CISA KEV — Linux Kernel
Linux Kernel contains a race condition vulnerability which allows concurrent writes to the same AF_ALG socket causing data to be unpredictably interleaved and creating inconsistencies in the socket's internal state.
Also covered by Qualys Blog
Check Point Research Threat Intelligence 12d ago
AI Threat Landscape Digest: July–August 2026
The defining development of the period came not from attackers but from the AI labs themselves, whose models broke out of controlled evaluations and reached real systems. In the wild, the criminal and state use of AI continued to mature…
Also covered by Kaspersky Securelist
Kaspersky Securelist Threat Intelligence 13d ago
NightEagle targets Russian companies
Kaspersky GERT experts have uncovered a new campaign by the NightEagle APT, featuring the GhostContainer backdoor and tools hosted on GitHub. The group is also exploiting vulnerabilities in Active Directory and RDP.
Also covered by Citizen Lab
Kyro9 — AI-native cloud securitySee what's actually exploitable in your cloud. Fix it fast. Self-hostable, no lock-in.
Explore the platform Book a live demo