<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Cyber Threat Intelligence 16 September 2026]]></title><description><![CDATA[<p dir="auto"><strong>Vulnerabilities</strong></p>
<ul>
<li><strong>Attackers Actively Exploiting Critical Vulnerability In WooCommerce Wholesale Lead Capture Plugin</strong><br />
"On February 20th, 2026, a critical Unauthenticated Arbitrary File Upload vulnerability was publicly disclosed in WooCommerce Wholesale Lead Capture, a premium WordPress plugin with an estimated 6,000 active installations. This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including PHP backdoors, and achieve remote code execution. We added this vulnerability to the Wordfence Intelligence vulnerability database on February 25th, 2026. The Wordfence Firewall has already blocked over 100,000 exploit attempts targeting this vulnerability."<br />
<a href="https://www.wordfence.com/blog/2026/09/attackers-actively-exploiting-critical-vulnerability-in-woocommerce-wholesale-lead-capture-plugin/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.wordfence.com/blog/2026/09/attackers-actively-exploiting-critical-vulnerability-in-woocommerce-wholesale-lead-capture-plugin/</a><br />
<a href="https://www.bleepingcomputer.com/news/security/hackers-target-wordpress-sites-via-third-party-woocommerce-plugin/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/hackers-target-wordpress-sites-via-third-party-woocommerce-plugin/</a></li>
<li><strong>Cisco Patches Secure Email Gateway Zero-Day Exploited In Attacks</strong><br />
"Cisco warned customers to patch a critical Secure Email Gateway zero-day security flaw that threat actors have been exploiting in attacks. "In September 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability," the company warned in a Monday security advisory. The security flaw (tracked as CVE-2026-76461) was found in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway and affects virtual and physical appliances, regardless of the device configuration."<br />
<a href="https://www.bleepingcomputer.com/news/security/new-cisco-secure-email-zero-day-exploited-to-execute-commands-as-root/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/new-cisco-secure-email-zero-day-exploited-to-execute-commands-as-root/</a><br />
<a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX" target="_blank" rel="noopener noreferrer nofollow ugc">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX</a><br />
<a href="https://thehackernews.com/2026/09/cisco-secure-email-gateway-flaw.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/09/cisco-secure-email-gateway-flaw.html</a><br />
<a href="https://securityaffairs.com/199137/hacking/cisco-warns-of-ongoing-exploitation-of-critical-email-gateway-zero-day.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://securityaffairs.com/199137/hacking/cisco-warns-of-ongoing-exploitation-of-critical-email-gateway-zero-day.html</a><br />
<a href="https://cyberscoop.com/cisco-secure-email-gateway-zero-day-exploited/" target="_blank" rel="noopener noreferrer nofollow ugc">https://cyberscoop.com/cisco-secure-email-gateway-zero-day-exploited/</a><br />
<a href="https://www.securityweek.com/root-rce-zero-day-in-cisco-secure-email-gateway-under-active-exploitation/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.securityweek.com/root-rce-zero-day-in-cisco-secure-email-gateway-under-active-exploitation/</a><br />
<a href="https://www.theregister.com/security/2026/09/15/cisco-email-security-boxes-can-be-rooted-by-an-email/5296604" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.theregister.com/security/2026/09/15/cisco-email-security-boxes-can-be-rooted-by-an-email/5296604</a><br />
<a href="https://www.helpnetsecurity.com/2026/09/15/cve-2026-76461-cisco-email-gateway-zero-day-exploited/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.helpnetsecurity.com/2026/09/15/cve-2026-76461-cisco-email-gateway-zero-day-exploited/</a></li>
<li><strong>Acronis Warns Of Actively Exploited Flaw In Its cPanel Backup Plugin</strong><br />
"Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. cPanel &amp; WHM and Plesk are used by web hosting companies and server administrators to manage websites and servers through graphical interfaces. Acronis’ backup add-ons connect the hosting control panel to the company's infrastructure, allowing administrators to back up and restore websites, files, databases, mailboxes, and hosting accounts from within the cPanel and Plesk interfaces."<br />
<a href="https://www.bleepingcomputer.com/news/security/acronis-warns-of-actively-exploited-flaw-in-its-cpanel-backup-plugin/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/acronis-warns-of-actively-exploited-flaw-in-its-cpanel-backup-plugin/</a></li>
<li><strong>Apple Patches 200 Vulnerabilities With New iOS 27, MacOS Golden Gate 27 Releases</strong><br />
"Apple on Monday announced patches for a record number of vulnerabilities across its desktop and mobile operating systems, including more than 200 flaws patched with the latest major releases: iOS 27 and macOS Golden Gate 27. iOS 27 and iPadOS 27 include fixes for about 126 security flaws, 20 of which affect the kernel. macOS Golden Gate 27 addresses 210 vulnerabilities, roughly 100 of which are shared with the iOS 27 release. macOS Tahoe 26.7 patches 153 unique CVEs, including 26 security defects in the kernel that could lead to memory corruption, privilege escalation, system termination, and information leaks."<br />
<a href="https://www.securityweek.com/apple-patches-200-vulnerabilities-with-new-ios-27-macos-golden-gate-27-releases/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.securityweek.com/apple-patches-200-vulnerabilities-with-new-ios-27-macos-golden-gate-27-releases/</a><br />
<a href="https://www.theregister.com/security/2026/09/15/the-vulnpocalypse-rains-ibugs-down-on-apple-with-record-setting-number-of-patches/5296679" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.theregister.com/security/2026/09/15/the-vulnpocalypse-rains-ibugs-down-on-apple-with-record-setting-number-of-patches/5296679</a></li>
<li><strong>CISA: Critical VMware RCE Flaw Now Exploited By Ransomware Gangs</strong><br />
"The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned security teams that ransomware gangs have now joined ongoing attacks exploiting a critical VMware vCenter vulnerability patched in July. Broadcom addressed the security flaw (tracked as CVE-2026-59310) on July 29, describing it as a critical directory traversal vulnerability in the vCenter Syslog server that unauthenticated attackers can exploit to execute arbitrary code."<br />
<a href="https://www.bleepingcomputer.com/news/security/cisa-critical-vmware-vcenter-rce-flaw-now-exploited-by-ransomware-gangs/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/cisa-critical-vmware-vcenter-rce-flaw-now-exploited-by-ransomware-gangs/</a></li>
<li><strong>LiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access On a Shared Server</strong><br />
"A critical vulnerability in LiteSpeed Web Server Enterprise could let a low-privilege website user gain root access on a shared-hosting server, cPanel warned in an advisory published on September 14. On such servers, many customers' sites run on a single machine, and an attacker with one of those hosting accounts could exploit the flaw to access or alter other sites and the server itself, according to the advisory. cPanel said it had received notice of the flaw, which affects versions before 6.3.7, and urged administrators to update to that release, which LiteSpeed published on September 11."<br />
<a href="https://thehackernews.com/2026/09/litespeed-enterprise-flaw-could-let-one.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/09/litespeed-enterprise-flaw-could-let-one.html</a><br />
<a href="https://securityaffairs.com/199127/security/shared-hosting-at-risk-litespeed-enterprise-bug-can-grant-root-from-a-single-tenant.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://securityaffairs.com/199127/security/shared-hosting-at-risk-litespeed-enterprise-bug-can-grant-root-from-a-single-tenant.html</a></li>
</ul>
<p dir="auto"><strong>Malware</strong></p>
<ul>
<li><strong>Malcious Admin Menu Editor Pro Plugin Backdoors 1,500 WordPress Sites</strong><br />
"Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer’s website and pushed updates that created a hidden user account. Developer Janis Elsts says an unauthorized party accessed the <a href="http://adminmenueditor.com" target="_blank" rel="noopener noreferrer nofollow ugc">adminmenueditor.com</a> website on Monday and uploaded version 2.35 as an update for the plugin’s Pro version. The update included an includes/wp-user-consent.php file that installed a web shell on affected websites."<br />
<a href="https://www.bleepingcomputer.com/news/security/malcious-admin-menu-editor-pro-plugin-backdoors-1-500-wordpress-sites/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/malcious-admin-menu-editor-pro-plugin-backdoors-1-500-wordpress-sites/</a><br />
<a href="https://adminmenueditor.com/blog/security-incident-affecting-customers-2026-09-14/" target="_blank" rel="noopener noreferrer nofollow ugc">https://adminmenueditor.com/blog/security-incident-affecting-customers-2026-09-14/</a></li>
<li><strong>The Banana Stand: Brokering And Managing Infections Across Asia Using MQTT</strong><br />
"Black Lotus Labs<img src="https://webboard-nsoc.ncsa.or.th/assets/plugins/nodebb-plugin-emoji/emoji/android/00ae.png?v=2sqmsl7eedm" class="not-responsive emoji emoji-android emoji--registered" style="height:23px;width:auto;vertical-align:middle" title=":registered:" alt="®" />, the threat research division at Lumen, uncovered BambooToken, an emerging malware family using the Message Queueing and Telemetry Transport (MQTT) to quietly control infected Windows and Linux systems. Active since at least 2023, the campaign points to a skilled threat actor using stealthy infrastructure, side-loading techniques and broad access to collect data from targeted environments across Asia and South America. The findings show how early detection, supply chain visibility and proactive threat mitigation can help expose discreet techniques before adversaries expand them against higher-value targets."<br />
<a href="https://www.lumen.com/blog/en-us/the-banana-stand-brokering-and-managing-infections-across-asia-using-mqtt" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.lumen.com/blog/en-us/the-banana-stand-brokering-and-managing-infections-across-asia-using-mqtt</a><br />
<a href="https://www.bleepingcomputer.com/news/security/bambootoken-malware-controls-windows-and-linux-systems-via-mqtt/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/bambootoken-malware-controls-windows-and-linux-systems-via-mqtt/</a><br />
<a href="https://thehackernews.com/2026/09/bambootoken-malware-uses-mqtt-to.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/09/bambootoken-malware-uses-mqtt-to.html</a></li>
<li><strong>Iranian Cyber Targeting Of Dissidents, Activists And Journalists</strong><br />
"CHOSEN BRICK is a malware family that has been used to target individuals around the world including in the UK, US and the Netherlands from at least 2025. CHOSEN BRICK enables Iranian state cyber actors to collect information on a target’s contacts, emails and social media messages, which could enable tracking of their movements. Iran almost certainly uses cyber activity to support the repression of individuals who are seen as a threat to the regime, such as dissidents, activists and journalists. In some cases, the Iranian intelligence services have plotted to kidnap or conduct lethal operations against individuals internationally, who they perceive as enemies of the regime."<br />
<a href="https://www.ncsc.gov.uk/news/iranian-cyber-targeting-of-dissidents-activists-and-journalists" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.ncsc.gov.uk/news/iranian-cyber-targeting-of-dissidents-activists-and-journalists</a><br />
<a href="https://www.bankinfosecurity.com/iranian-hackers-dodging-corporate-defenses-to-reach-critics-a-32822" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bankinfosecurity.com/iranian-hackers-dodging-corporate-defenses-to-reach-critics-a-32822</a></li>
<li><strong>VectraRAT: An Undocumented Full-Stack MaaS Built From Scratch</strong><br />
"SOCRadar’s Threat Research Unit (STRU) has documented VectraRAT, a Malware-as-a-Service platform built entirely from scratch rather than forked from leaked RAT code. Renting from $250 a month, it gives operators hidden-desktop control, keylogging, clipboard hijacking, browser credential theft, and a UAC bypass that elevates with no prompt. The operator “Vectra” is a rebrand of “Nyxel”, active since at least August 2022 with no prior public reporting. STRU traced live infrastructure from an exposed open directory across more than ten servers and campaigns using Amadey and ClickFix, where 48% of recovered victim entries were corporate Windows editions, including exfiltration from Windows Server 2025."<br />
<a href="https://socradar.io/blog/vectrarat-undocumented-stack-maas/" target="_blank" rel="noopener noreferrer nofollow ugc">https://socradar.io/blog/vectrarat-undocumented-stack-maas/</a><br />
<a href="https://www.darkreading.com/endpoint-security/vectrarat-hack-windows-enterprises" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.darkreading.com/endpoint-security/vectrarat-hack-windows-enterprises</a></li>
<li><strong>Search Results Are Sending People To Fake Bitrefill Checkouts</strong><br />
"Bitrefill is a legitimate company that sells gift cards for popular stores like Amazon, Deliveroo, Apple, Nintendo, and thousands of others. They also sell eSIMs, and mobile top-ups. You can pay on their website for all of these with cryptocurrency. The scam is designed to catch people searching for Bitrefill or something it sells, like a gift card. Victims see a search result that appears to lead to Bitrefill but actually points to a lookalike domain. The fake site then takes them through what appears to be a normal purchase. The fake sites are not operated by or affiliated with Bitrefill; scammers have copied its branding and checkout process."<br />
<a href="https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts</a></li>
<li><strong>The Extension You Never Installed: KREMLIN Forges Chrome's Own Integrity Checks To Steal Banking Sessions</strong><br />
"Elastic Security Labs has tracked REF9334, a Brazilian banking malware operation, since May 2025. Its toolkit is called KREMLIN (as named by the malware author, Kr3mlin4rt1st), though nothing about the operation is Russian. Lures impersonate twelve Brazilian banks; error messages and code comments are written in Portuguese, and the operators' Ethereum transactions cluster during São Paulo working hours. Over 15 months and seven campaigns, they built a malicious browser extension that installs itself in Chrome and Edge, and the browser then loads it as though the user approved it. This post covers the infection chain, the extension internals, all seven campaigns, and the wallet trail connecting them."<br />
<a href="https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware</a><br />
<a href="https://thehackernews.com/2026/09/kremlin-banking-malware-hijacks-chrome.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/09/kremlin-banking-malware-hijacks-chrome.html</a></li>
<li><strong>Iranian Hackers Use Telegram-Controlled Malware To Spy On Dissidents And Journalists</strong><br />
"Cybersecurity agencies in the United States, the United Kingdom, and the Netherlands have detailed a Windows malware that they say Iran's intelligence service uses to spy on dissidents, journalists, and activists around the world. The malware is controlled via the Telegram messaging app and can copy a target's emails and chat messages, take screenshots, and activate the microphone to record audio. The FBI calls it HEAVYGRAM, and the U.K.'s National Cyber Security Center (NCSC) calls it CHOSEN BRICK."<br />
<a href="https://thehackernews.com/2026/09/iranian-hackers-use-telegram-controlled.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/09/iranian-hackers-use-telegram-controlled.html</a><br />
<a href="https://www.ic3.gov/CSA/2026/260915-2.pdf" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.ic3.gov/CSA/2026/260915-2.pdf</a><br />
<a href="https://therecord.media/iran-cyber-spies-use-fake-mri-scans-as-lure" target="_blank" rel="noopener noreferrer nofollow ugc">https://therecord.media/iran-cyber-spies-use-fake-mri-scans-as-lure</a><br />
<a href="https://www.theregister.com/security/2026/09/15/iranian-spies-hit-windows-machines-with-chosen-brick-data-stealing-malware/5296646" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.theregister.com/security/2026/09/15/iranian-spies-hit-windows-machines-with-chosen-brick-data-stealing-malware/5296646</a></li>
<li><strong>Mind The (Patch) Gap: Multiple Chinese Threat Actors Chain 0-Day Exploits In Chrome &amp; Windows</strong><br />
"On September 1, 2026, Volexity’s Network Security Monitoring (NSM) service detected a spear-phishing campaign from a Chinese threat actor it tracks as UTA0560 targeting customers at multiple non-governmental organizations (NGOs). The emails contained a message encouraging the users to a click a link that led to the website of a US-based university. These links abused a reflected cross-site scripting (XSS) vulnerability on the website, redirecting recipients to threat-actor-controlled infrastructure hosting a multi-stage exploit chain that included a Google Chrome zero-day, CVE-2026-85046. Volexity analyzed its email telemetry and discovered that another Chinese threat actor it tracks as JungleBamboo (also known as APT31/Violet Typhoon/TA412) was also exploiting the same vulnerability chain against a different set of targets using different infrastructure and post-exploitation malware."<br />
<a href="https://www.volexity.com/blog/2026/09/09/mind-the-patch-gap-multiple-chinese-threat-actors-chain-0-day-exploits-in-chrome-windows/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.volexity.com/blog/2026/09/09/mind-the-patch-gap-multiple-chinese-threat-actors-chain-0-day-exploits-in-chrome-windows/</a><br />
<a href="https://thehackernews.com/2026/09/china-linked-hackers-exploit-chrome.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/09/china-linked-hackers-exploit-chrome.html</a><br />
<a href="https://securityaffairs.com/199104/apt/one-exploit-chain-two-espionage-campaigns-chrome-and-windows-under-fire.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://securityaffairs.com/199104/apt/one-exploit-chain-two-espionage-campaigns-chrome-and-windows-under-fire.html</a></li>
<li><strong>How Money Laundering, Scams, And Espionage Hide In a Web Full Of Casino Garbage</strong><br />
"Many security teams ignore online gambling and casino domains, especially Chinese-language websites. Over the last decade there’s been massive growth in both gambling websites catering to Chinese audiences and similar casino sites targeting people all over the world. There’s also been growth in legal gambling and casino websites, but the scale of these compared to the malicious casinos is marginal."<br />
<a href="https://www.infoblox.com/blog/threat-intelligence/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.infoblox.com/blog/threat-intelligence/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage/</a><br />
<a href="https://www.theregister.com/security/2026/09/15/low-quality-casino-sites-conceal-highly-dangerous-threat-actors/5296652" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.theregister.com/security/2026/09/15/low-quality-casino-sites-conceal-highly-dangerous-threat-actors/5296652</a></li>
<li><strong>Google Doc Sidebar Sends Mac And Windows Users Down Different Paths To Malware</strong><br />
"Many Black Hat and DEFCON attendees come home to an inbox full of DMs. While catching up on the expected post-conference networking last month, a Huntress researcher realized they were being targeted in an X exchange with someone posing as a crypto marketing executive. The threat actor sent a link to a real Google Doc with a custom sidebar designed to trick the recipient into downloading malware: an AMOS infostealer on macOS, or PowerShell loader chain on Windows. Immediately picking up on the scam, our researcher didn't download any malware on their machine, but they did keep chatting with the threat actor, who ended up sending more malware and eventually a million-dollar offer. What started with a DM ended with a rogue certificate authority sitting in the Huntress testing environment."<br />
<a href="https://www.huntress.com/blog/google-doc-sidebar-malware-mac-windows" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.huntress.com/blog/google-doc-sidebar-malware-mac-windows</a></li>
</ul>
<p dir="auto"><strong>Breaches/Hacks/Leaks</strong></p>
<ul>
<li><strong>CenterPoint Energy Confirms Customer Data Stolen In Cyberattack</strong><br />
"CenterPoint Energy disclosed a breach compromising some customers’ personal information after an attacker leaked data allegedly stolen from the utility company. An investigation started after the company discovered an online post from a threat actor claiming to have stolen 7.49 million records. CenterPoint Energy is a Houston-based public utility company that provides electric and natural gas services and operates power generation facilities."<br />
<a href="https://www.bleepingcomputer.com/news/security/centerpoint-energy-confirms-customer-data-stolen-in-cyberattack/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/centerpoint-energy-confirms-customer-data-stolen-in-cyberattack/</a><br />
<a href="https://therecord.media/centerpoint-energy-data-breach" target="_blank" rel="noopener noreferrer nofollow ugc">https://therecord.media/centerpoint-energy-data-breach</a><br />
<a href="https://www.securityweek.com/texas-utility-centerpoint-energy-confirms-breach-after-hacker-leaks-data/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.securityweek.com/texas-utility-centerpoint-energy-confirms-breach-after-hacker-leaks-data/</a></li>
</ul>
<p dir="auto"><strong>General News</strong></p>
<ul>
<li><strong>CVE Authorities Make Score 8 Look More Like The New 10</strong><br />
"The U.S. government-backed CVE program is the gold standard for cataloging vulnerabilities, but its CVSS scores should be taken with a grain of salt, as the numbers can fluctuate for the same bug. Under version 4.0 of the scoring system, vendors assign a base score reflecting a vulnerability's highest possible severity, while threat factors such as whether exploitation has been observed can later modify the threat-adjusted score. "We need to stop talking about 'the CVSS score' as though there is only one number," Douglas McKee, director of vulnerability intelligence at Rapid7, told ISMG."<br />
<a href="https://www.bankinfosecurity.com/cve-authorities-make-score-8-look-more-like-new-10-a-32829" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bankinfosecurity.com/cve-authorities-make-score-8-look-more-like-new-10-a-32829</a></li>
<li><strong>Your Employees Are Already Using AI Tools You Never Approved</strong><br />
"Seventy-four percent of respondents report departmental or scaled AI adoption at their organizations, including within individual teams or departments, across business functions, and as part of processes and operations, according to the latest OneTrust 2026 AI-Ready Governance Report. The remaining respondents are planning, evaluating, or experimenting with AI, while 1% report no AI use."<br />
<a href="https://www.helpnetsecurity.com/2026/09/15/onetrust-enterprise-ai-governance-trends-report/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.helpnetsecurity.com/2026/09/15/onetrust-enterprise-ai-governance-trends-report/</a></li>
<li><strong>Most Chief Audit Executives Can’t Tell You What AI Is Worth Yet</strong><br />
"Auditors are using AI in their daily work, and their departments have mostly left them to figure it out alone. 93% of audit leaders and auditors report some level of AI use, while 15% say their department has deployed formal use cases and runs them routinely in audits, according to Gartner. Chief audit executives (CAE) have to defend that arrangement to stakeholders, and most of them cannot say what it returns. Of the 142 CAEs polled in May, 54% have not started measuring the value of audit’s use of AI. Seven percent tie AI to cost metrics such as reduced external spend or avoided hiring, which is worth remembering the next time someone suggests the tools should pay for themselves in headcount."<br />
<a href="https://www.helpnetsecurity.com/2026/09/15/gartner-ai-in-internal-audit/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.helpnetsecurity.com/2026/09/15/gartner-ai-in-internal-audit/</a></li>
<li><strong>Most Fraudulent Hires Receive Credentials Before Detection</strong><br />
"Most fraudulent hires receive corporate credentials and internal network access before being detected, according to a new report by HYPR. Fraudulent candidates successfully navigate pre-hire screening and take up their roles in 42% cases. Just 3% are subsequently detected as fraudulent on the same day as they are officially hired. Around a third (32%) are discovered within one to three days, 45% within four to six days and 20% go undetected for up to three weeks. This means that fraudulent hires have an average of 5.73 days of unmonitored access to corporate networks, posing significant data security risks to organizations."<br />
<a href="https://www.infosecurity-magazine.com/news/fraudulent-hires-credentials/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.infosecurity-magazine.com/news/fraudulent-hires-credentials/</a></li>
<li><strong>The State Of Recoverability 2026</strong><br />
"Cybersecurity has spent two decades organized around a single idea: keep them out. That idea is being retired as the measure of success. Gartner now advises security leaders to define success around resilience rather than prevention, on the grounds that resilience, unlike absolute security, can be tested, practiced, measured, and improved. Regulators are now writing recovery obligations into law, insurers are pricing recovery posture into premiums, and boards have stopped asking if the organization is secure and started asking how long it would be down."<br />
<a href="https://fenix24.com/2026-state-of-recoverability-report/" target="_blank" rel="noopener noreferrer nofollow ugc">https://fenix24.com/2026-state-of-recoverability-report/</a><br />
<a href="https://www.infosecurity-magazine.com/news/four-of-800-clients-hit-ransomware/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.infosecurity-magazine.com/news/four-of-800-clients-hit-ransomware/</a></li>
<li><strong>“We Think The Security Control Is Working” Is No Longer Good Enough</strong><br />
"Security, risk, and control assessments are typically done for the sake of compliance: tools deployed, audits passed, workflows completed, boxes checked. That’s no longer enough for boards, customers, and regulators, who all want an answer to a harder question: ‘can you prove your controls are working right now?’ I often ask CISOs a version of that question, and the honest answer is usually some form of “we think so.” It’s not because they’re careless. Most control checks still happen the way a dentist visit does. When your dentist asks whether you brush and floss every day, you could fib and say yes, but one look at your x-ray tells the real story."<br />
<a href="https://www.securityweek.com/we-think-the-security-control-is-working-is-no-longer-good-enough/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.securityweek.com/we-think-the-security-control-is-working-is-no-longer-good-enough/</a></li>
<li><strong>Swiss Court Sentences 52-Year-Old Ukrainian Ransomware Dev To Nearly 13 Years In The Cooler</strong><br />
"A Swiss court has sentenced a 52-year-old Ukrainian ransomware developer to 12 years and nine months in prison for his role in attacks on companies including Stadler Rail. Zurich District Court found that the man developed LockerGoga, MegaCortex, and Nefilim, but was not the mastermind behind the operations. He also received a ten-year ban from Switzerland. The judgment is not final and can be appealed. He had been held in pretrial detention since October 2021 and consistently denied knowing that his software was being used for criminal purposes."<br />
<a href="https://www.theregister.com/security/2026/09/15/swiss-court-sentences-52-year-old-ukrainian-ransomware-dev-to-nearly-13-years-in-the-cooler/5296482" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.theregister.com/security/2026/09/15/swiss-court-sentences-52-year-old-ukrainian-ransomware-dev-to-nearly-13-years-in-the-cooler/5296482</a></li>
</ul>
<p dir="auto"><strong>อ้างอิง</strong><br />
Electronic Transactions Development Agency (ETDA) <img src="/assets/uploads/files/1789557363149-1d813dc0-8ebe-4f5c-84aa-5d4dab6c7b70-image.png" alt="1d813dc0-8ebe-4f5c-84aa-5d4dab6c7b70-image.png" class=" img-fluid img-markdown" /></p>
]]></description><link>https://webboard-nsoc.ncsa.or.th/topic/3299/cyber-threat-intelligence-16-september-2026</link><generator>RSS for Node</generator><lastBuildDate>Wed, 16 Sep 2026 14:31:12 GMT</lastBuildDate><atom:link href="https://webboard-nsoc.ncsa.or.th/topic/3299.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 16 Sep 2026 11:16:13 GMT</pubDate><ttl>60</ttl></channel></rss>