Cyber Threat Intelligence 17 September 2026
-
Industrial Sector
- Digital Watchdog VMAX DVR And NVR Product Lineups
"Successful exploitation of these vulnerabilities could grant full administrative control of the device, allowing an attacker to view live and recorded surveillance, alter device configurations, and use the device as a network pivot point."
https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-01 - MySCADA MyPRO Manager
"Successful exploitation of these vulnerabilities could allow an attacker to access privileged management functions or send arbitrary SMS messages through the connected GSM modem."
https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-03 - Siemens Reyrolle 7SR5
"Siemens Reyrolle 7SR5 Before V2.70 is affected by multiple vulnerabilities. Siemens has released a new version for Reyrolle 7SR5 and recommends to update to the latest version."
https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-05 - Wärtsilä FOS-Onboard
"Successful exploitation of these vulnerabilities could allow an attacker to deliver an unauthorized update, execute code, or extract credentials to allow the attacker to impersonate a privileged client."
https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-02 - Siemens Mendix SAML
"Mendix SAML module contains a vulnerability that could allow unauthenticated remote attackers to hijack an account in specific SSO configurations. Mendix has provided fix releases for the Mendix SAML module and recommends to update to the latest version."
https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-06 - Schneider Electric SCADAPack x70 Products
"Schneider Electric is aware of a vulnerability in its SCADAPack x70 products. The SCADAPack 47x, SCADAPack 47xi, SCADAPack 47xd, SCADAPack 470R and SCADAPack 57x products are Remote Terminal Units that provide communication capabilities for remote monitoring and control. Failure to apply the mitigations provided below may increase the risk of unauthorized access to RTU configuration through the Secure Lock functionality, potentially resulting in a loss of confidentiality."
https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-04 - Siemens Teamcenter
"A reflected cross site scripting vulnerability in the authentication redirect flow (/auth/) of Teamcenter allows an unauthenticated remote attacker to inject JavaScript into an authenticated user's session by crafting a malicious URL. Successful exploitation may enable the attacker to read data or perform actions within the victim's Teamcenter session. Siemens has released new versions for the affected products and recommends to update to the latest versions."
https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-07 - CareCam CM2507
"Successful exploitation of these vulnerabilities could allow an attacker to access live video and sensitive device information, enable unauthorized services, execute arbitrary code, modify device operation, and recover stored credentials."
https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-08
New Tooling
- DeepZero: Open-Source Hunting For Vulnerable Windows Drivers
"DeepZero is an open-source engine that automates the search for exploitable Windows kernel drivers. You point it at a folder of binaries and it parses them, pulls them apart, scans them, throws most of them away, and asks a language model whether what survives can be attacked. Pipelines are written in YAML, the code is Python 3.11 and up. Rehman Ahmadzai, who maintains the project, said DeepZero has “found multiple verified vulnerabilities in a subset of the Snappy Driver Installer corpus, with some still undergoing the disclosure process.” The bundled pipeline targets BYOVD, short for bring your own vulnerable driver: an attacker loads a legitimately signed driver that contains a flaw and uses it to reach the kernel."
https://www.helpnetsecurity.com/2026/09/16/vulnerable-windows-drivers-deepzero-open-source/
https://github.com/416rehman/DeepZero
Vulnerabilities
- Oracle Patches 800+ Vulnerabilities In September 2026 Security Update
"Oracle on Tuesday announced the release of 673 new security patches as part of its September 2026 Critical Security Patch Update (CSPU). The security updates appear to resolve more than 800 vulnerabilities: there are 672 unique CVEs in the 17 risk matrices included in the September 2026 CSPU advisory, but Oracle also notes that more than 130 additional CVEs have been resolved with the patches for other flaws. More than 100 of the newly addressed security defects are critical-severity flaws, and over 240 are remotely exploitable without authentication."
https://www.securityweek.com/oracle-patches-800-vulnerabilities-in-september-2026-security-update/ - Wordfence Argus Identifies Two Critical Unauthenticated Vulnerability Chains Leading To Remote Code Execution In The Events Calendar Plugin
"On August 21 and August 22, 2026, Wordfence Argus, created by the Wordfence Threat Intelligence team, identified two independent critical vulnerability chains in The Events Calendar, a WordPress plugin active on more than 600,000 websites. Both chains begin in the plugin’s widget-rendering pipeline and can ultimately lead to Remote Code Execution without authentication through two separate methods. The first chain uses PHP Object Injection to execute arbitrary operating system commands on the underlying server. The second chain bypasses the object-injection guard and abuses an arbitrary-callable primitive to reset an administrator’s password, after which an attacker can upload a malicious plugin and take complete control of the site."
https://www.wordfence.com/blog/2026/09/wordfence-argus-identifies-two-critical-unauthenticated-vulnerability-chains-leading-to-remote-code-execution-in-the-events-calendar-plugin/
https://www.securityweek.com/unauthenticated-rce-flaws-could-expose-200000-wordpress-sites-to-takeover/
https://hackread.com/critical-calendar-wordpress-plugin-flaws-site-takeover/ - Google Fixes Actively Exploited Android Zero-Day On Pixel Devices
"Google has released the September 2026 security patches to address 110 vulnerabilities affecting its Pixel devices, including one zero-day flaw actively exploited in targeted attacks. "There are indications that CVE-2026-58704 may be under limited, targeted exploitation," the company warned on Wednesday. "All supported Google devices will receive an update to the 2026-09-05 patch level. We encourage all customers to accept these updates to their devices.""
https://www.bleepingcomputer.com/news/security/google-fixes-actively-exploited-android-zero-day-on-pixel-devices/
https://thehackernews.com/2026/09/google-patches-pixel-modem-flaw-amid.html
https://www.malwarebytes.com/blog/mobile/2026/09/google-pixel-owners-urged-to-patch-actively-exploited-modem-flaw
https://www.securityweek.com/pixel-modem-zero-day-exploited-in-targeted-attacks/
https://securityaffairs.com/199193/hacking/google-patches-pixel-modem-zero-day-exploited-in-targeted-attacks.html - Chrome, Firefox Updates Patch 115 Vulnerabilities
"Google and Mozilla have released fresh security updates for Chrome and Firefox users, resolving a total of 115 vulnerabilities. The new Chrome 153 release patches 42 security defects, including three critical-severity and 28 high-severity bugs. The critical flaws include CVE-2026-91726, an out-of-bounds read in WebGL, and CVE-2026-91721 and CVE-2026-91749, use-after-free issues in Internals and Workers, respectively."
https://www.securityweek.com/chrome-firefox-updates-patch-115-vulnerabilities/ - Issabel Framework Hard-Coded JWT Key RCE Via Pbxapi/manager/originate
"The Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf contains a hard-coded HS256 JWT signing key in the pbxapi index.php file that is identical across every installation, allowing unauthenticated remote attackers to forge valid bearer tokens. Attackers can use the forged token to call the manager originate endpoint with the System application parameter, causing Asterisk to execute arbitrary OS commands as the Asterisk user. Exploitation evidence was first observed by the Shadowserver Foundation on 2026-09-09."
https://www.vulncheck.com/advisories/issabel-pbx-hard-coded-jwt-key-rce-via-pbxapi-manager-originate
https://thehackernews.com/2026/09/attackers-exploit-issabel-framework.html - Authentication Bypass And DoS Vulnerabilities: OPSWAT Discovers CVE-2026-15315 & CVE-2026-15316 In TP-Link Tapo Cameras
"TP-Link Tapo cameras are widely used smart security devices designed for home and small-business monitoring. As network-connected cameras, these devices combine video streaming, remote management, mobile application integration, and other services within a compact embedded system. This connectivity also makes security especially important. A vulnerability that allows an attacker to bypass authentication or access privileged functionality could compromise the camera and potentially provide a foothold within the network where the device is deployed."
https://www.opswat.com/blog/authentication-bypass-and-dos-vulnerabilities-opswat-discovers-cve-2026-15315-cve-2026-15316-in-tp-link-tapo-cameras
https://www.infosecurity-magazine.com/news/zeroday-tplink-cameras/ - ParaShells: Parallels Desktop Turns Appliance Install Into a Root Shell
"Your Mac runs a vulnerable version of Parallels Desktop. A malicious package, compromised CI job, or other unprivileged process is already running on it. No admin access. No Parallels-signed client. One appliance-install request later, attacker-controlled code runs as root. While testing Desktop 26.4.0 (build 57513) on Apple silicon, we found that an unprivileged local user could execute code as root through prl_disp_service. The exploit combines its world-writable Unix socket with weak local-client authentication and argument injection in the appliance extraction path."
https://jfrog.com/blog/parallels-desktop-turns-appliance-install-into-root-shell/
https://www.helpnetsecurity.com/2026/09/16/parallels-desktop-cve-2026-90894-parashells-vulnerability/ - CISA Adds One Known Exploited Vulnerability To Catalog
"CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
CVE-2026-58704 Google Pixel Improper Authorization Vulnerability"
https://www.cisa.gov/news-events/alerts/2026/09/16/cisa-adds-one-known-exploited-vulnerability-catalog - CISA Adds Two Known Exploited Vulnerabilities To Catalog
"CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
CVE-2026-76460 Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability
CVE-2026-87886 Acronis Backup Incorrect Default Permissions Vulnerability"
https://www.cisa.gov/news-events/alerts/2026/09/16/cisa-adds-two-known-exploited-vulnerabilities-catalog
Malware
- Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens
"A critical security flaw in WSO2 API Manager has come under active exploitation in the wild, according to findings from watchTowr. The vulnerability, tracked as CVE-2026-5430 (CVSS score: 9.8/10.0), is a case of improper verification of a cryptographic signature that could result in account takeover. Hacktron Team has been credited with discovering and reporting the flaw. "JWT authentication can be bypassed when a token is signed using an unsupported algorithm, allowing unauthorized access," according to an advisory released by WSO2 in May 2026. "Successful exploitation of the vulnerability may lead to unauthorized access, including potential compromise of administrative accounts and full account takeover.""
https://thehackernews.com/2026/09/active-exploitation-attempts-target.html
https://www.securityweek.com/enterprises-warned-of-attacks-exploiting-wso2-vulnerability/ - Critical ScreenConnect Flaw Now Actively Exploited In Attacks
"Attackers now exploit a critical-severity ConnectWise ScreenConnect vulnerability in the wild, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). ConnectWise shared temporary mitigation measures for this missing-authorization flaw on September 7, advising security teams to disable TransferFiles permissions to block potential attacks. The vulnerability (now tracked as CVE-2026-84869 and patched in ScreenConnect 26.6.5 and later) affects ScreenConnect clients and can let threat actors with basic privileges transfer or execute files in low-complexity attacks that don't require user interaction."
https://www.bleepingcomputer.com/news/security/cisa-warns-of-hackers-exploiting-critical-screenconnect-flaw/ - AI Helps Scammers Build Convincing Antivirus Renewal Pages
"Antivirus renewal scams often begin with a message claiming that your subscription has automatically renewed. When you follow the instructions to cancel it, you are taken to a fake page designed to collect your contact details. The renewal charge never existed. Receiving a message that names the antivirus software you use does not necessarily mean the sender has access to your device or account. Scammers impersonate popular brands and send the same message to large numbers of people, knowing that some recipients will be customers."
https://www.malwarebytes.com/blog/threat-intel/2026/09/ai-helps-scammers-build-convincing-antivirus-renewal-pages - NightEagle Targets Russian Companies
"Over the past year, our Global Emergency Response Team (GERT) has investigated several incidents involving the NightEagle group (APT-Q-95). This group has been active since at least 2023 and originally focused on organizations in Asia, as we reported previously. We have now identified attacks by the group targeting businesses in Russia. This post examines both known and new tools NightEagle used in its latest campaign."
https://securelist.com/tr/nighteagle-apt-ghostcontainer-and-tunneling/121323/
https://thehackernews.com/2026/09/three-threat-groups-target-russian.html - Atomic MacOS (AMOS) Stealer Activity
"This article reviews an Atomic macOS (AMOS) stealer malware infection generated in a lab environment. While several sources have published articles analyzing AMOS stealer, the associated indicators constantly change. This article presents a snapshot of indicators seen in early August 2026 and is designed to help readers better understand AMOS stealer."
https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/ - Scammers Are Watching Airline Complaints And Posing As Customer Support
"A delayed flight. Missing luggage. A refund that never arrived. For frustrated customers, social media has become a direct route to customer support. They tag the company, explain the problem, and wait for a response. However, threat actors are watching those same conversations. A Check Point Exposure Management investigation uncovered a coordinated social engineering campaign in which scammers monitor public complaints, impersonate customer support accounts, and approach customers seeking help. Researchers engaged directly with the scammers and followed the attack from the first social media interaction through WhatsApp conversations and payment flows."
https://blog.checkpoint.com/exposure-management/scammers-are-watching-airline-complaints-and-posing-as-customer-support/ - N0va Phishkit Targets US And EU Businesses: A New Challenge For Identity Security
"N0va is targeting organizations across North America and Europe with phishing campaigns that impersonate trusted services and abuse legitimate authentication flows. Successful attacks can give threat actors access to valid accounts without relying on obvious malware activity. From there, a single compromised identity can open the door to sensitive data, business systems, and additional cloud resources. The longer that access goes unnoticed, the greater the potential for wider compromise, operational disruption, and financial loss."
https://thehackernews.com/2026/09/n0va-phishkit-targets-us-and-eu.html - BragJack: How We Hijacked 5 Of The World's Most Popular Browsers Using Their Built-In AI Assistants
"We just hacked 5 of the world’s most popular browsers using a brand-new technique that relies on AI. And we don’t mean “some AI hacking model that we trained”. No no no… we mean the browser’s own built-in AI assistants that you probably have installed right now. Yes, if you’re using Google Chrome, Microsoft Edge, Opera Neon, Perplexity Comet, or Claude in Chrome… that means you. The interesting thing is that we didn’t even have to bypass the AI’s guardrails to do it. In fact, we didn’t even use prompt injection, because we discovered something worse."
https://forever.security/blog/bragjack-hijacking-5-browsers-via-built-in-ai-assistants
https://thehackernews.com/2026/09/one-extension-could-hijack-ai.html
https://www.darkreading.com/endpoint-security/bragjack-browser-agentic-ai - Operation RapidRust: APT36 Deploys RUSTYSHADE, RUSTYMOVE, PSNATCH, And BASHNATCH
"In August 2026, Zscaler ThreatLabz observed new activity by the Pakistan-nexus threat actor APT36 in a campaign we’re tracking as Operation RapidRust. Since our last publication about the group’s activity in January 2026, APT36 has maintained a high operational tempo and updated their tactics, techniques, and procedures (TTPs) in continued attacks targeting government and defense organizations in India and Afghanistan. During our investigation, ThreatLabz discovered new malware families and post-compromise tools, as well as significant post-compromise activity. The new tools include the RUSTYSHADE backdoor, the RUSTYMOVE post-compromise tool, and the PSNATCH and BASHNATCH file-stealing tools."
https://www.zscaler.com/blogs/security-research/operation-rapidrust-apt36-deploys-rustyshade-rustymove-psnatch-and - PhantomRaven: An LLM-Generated Information Stealer Developed For Bug Bounty Hunting
"CrowdStrike Counter Adversary Operations identified a financially motivated threat actor who works as a bug bounty hunter and who developed and distributed the JavaScript (JS)-based information stealer PhantomRaven via npm, a platform on which developers can access open-source packages to build applications and software. The developer likely wrote the malware using a large language model (LLM), an assessment made with high confidence based on verbose comments, placeholder code, and statistical token-analysis patterns."
https://www.crowdstrike.com/en-us/blog/phantomraven-llm-generated-information-stealer-for-bug-bounty-hunting/
https://hackread.com/crowdstrike-ai-phantomraven-malware-bug-bounty-hunter/ - Silent Push Exposes North Korean IT Worker Recruiting Facilitators Through Discord Servers
"Silent Push identified a North Korean fake job recruitment scam channel hosted on a Discord server by a defender colleague, and we engaged the recruitment representative to ask about their offering and determine whether the individual was actually a North Korean IT worker. After connecting via Telegram, we asked the suspect NK persona “Tec Guru” about virtual private networks (VPNs); they advised us to use Astrill VPN, a VPN often used by North Korean IT workers We identified the threat actor’s primary tactic as identity and proxy theft, under the guise of a front/facilitator recruitment scheme."
https://www.silentpush.com/blog/nk-it-worker/ - Mythic C2 Activity At Internet Scale
"Mythic was created as a successor to an earlier macOS-focused project (Apfell). It was designed as a language-agnostic, cross-platform framework with a web-based UI. It is provided in a dockerfile to suit your environment with the ability to choose and configure separately available agents. This modular design lets operators combine agents for different platforms with various transport profiles without modifying the core framework. These agents, C2 profiles, wrappers, and services are shared and supported by the Mythic Community."
https://censys.com/blog/mythic-c2/ - TrustSink: How a Rogue External MFA Provider Steals Passwords
"Varonis Threat Labs identified a credential-phishing technique we call TrustSink. It turns a trusted external authentication provider into a persistent credential trap within a legitimate sign-in flow. While the technique can work in any provider, we demonstrated TrustSink end-to-end using Microsoft Entra. An attacker with high privileges can register a rogue External Authentication Method (EAM) and place a convincing password page inside the legitimate sign-in flow. The page captures the password in plaintext while the provider returns a valid signed token, completing the login without an error."
https://www.varonis.com/blog/trustsink
Breaches/Hacks/Leaks
- 280,000 Impacted By Premier Medical Group Data Breach
"New York healthcare provider Premier Medical Group (PMG) is notifying over 280,000 patients that their personal and medical information was stolen in a data breach. PMG offers in-depth patient care across cardiology, dermatology, gastroenterology, neurology, plastic surgery, gynecology, and internal medicine fields through multiple office locations in the Hudson Valley. The data breach occurred in June, when some of PMG’s systems were disrupted, the healthcare provider said in an incident notice."
https://www.securityweek.com/280000-impacted-by-premier-medical-group-data-breach/ - International Meteor Organization Says Cyberattack Dealt ‘critical Blow’ To Website
"A cyberattack has shut down the website of the premier international organization responsible for tracking meteors. The International Meteor Organization (IMO) has continued tracking asteroids and meteor through its Facebook page, but its website now carries a static page notifying visitors of the cyberattack. “We recently suffered a cyberattack that dealt a critical blow to aging infrastructure, taking much of our site offline,” the organization said. “We expect several weeks of partial downtime as we transition to new infrastructure and services. We will bring features back as they become available.”"
https://therecord.media/international-meteor-organization-cyberattack
General News
- Securing The Unpatchable In An Age Of AI-Driven Vulnerabilities
"AI-assisted code analysis is uncovering decades of technical debt. Every new patch removes a newly identified coding mistake. Little by little, we are improving the state of software engineering, but the price is a cadence of patching that organizations may struggle to implement. These efforts leave unsupported systems, or systems that are not able to be patched for whatever reason, with unmitigated known vulnerabilities. How can such systems be secured in a world where AI is steadily improving its ability to identify new vulnerabilities?"
https://blog.talosintelligence.com/securing-the-unpatchable-in-an-age-of-ai-driven-vulnerabilities/ - The Adversary We Are Fighting Is Now a Full-Force Industry: Inside Cybercrime's New Economy
"The disruption we’re witnessing isn’t because of a new threat category. It is the industrialization of conventional ones. Cybercrime went corporate years ago: affiliate programs, Ransomware-as-a-Service (RaaS), Initial Access Brokers (IABs), support desks on underground portals. AI did not start that but what it did was collapse the cost and the skill floor of every stage of the attack at the same time. Attacks did get smarter, but the part most underestimate is that mediocre attackers became competent, and competent ones became industrial."
https://www.group-ib.com/blog/adversary-full-force-industry/ - NIST And CISA Finalize Playbook To Stop Token Theft And Forgery
"NIST and CISA have finalized guidelines to help federal agencies and cloud service providers (CSPs) protect identity and access tokens from forgery, theft, and misuse. The guidance, Protecting Tokens and Assertions from Forgery, Theft, and Misuse (NIST IR 8587), explains how agencies and cloud providers can strengthen key management, token verification, and token lifecycle controls. It also covers how identity providers and authorization servers should be designed and managed."
https://www.helpnetsecurity.com/2026/09/16/nist-cisa-cloud-token-security-guidance/
https://nvlpubs.nist.gov/nistpubs/ir/2026/NIST.IR.8587.pdf
https://www.infosecurity-magazine.com/news/cisa-nist-cloud-identity-token/ - What Happens When AI Agent Governance Is Missing At Scale
"In this interview with Help Net Security, Gourab Basu, Global Head of Engineering at meshIQ, discusses governance in AI agent systems. He argues that instructions written into a prompt are not enough to control what an agent does, since agents can change their own path as they work. Real control means checking proposed actions before they reach production systems, such as pausing a large refund for human approval. He also covers what breaks when a company scales from ten agents to a thousand, and how to build governance that works across different agent frameworks."
https://www.helpnetsecurity.com/2026/09/16/gourab-basu-meshiq-ai-agent-governance/ - The Modern Attack Chain: Rethinking Google Workspace Security In The Age Of AI
"Over the past two months, I’ve written about the Vercel breach and the Composio breach separately. Both offer lessons to learn on their own. But reading them together, I keep coming back to the same observation: these aren’t isolated incidents. They’re the same attack, run twice, against different targets, where email was not the entry point into the workspace. And once you see the pattern clearly, it changes what you think you need to defend. It also raises an uncomfortable question that I’ve been sitting with. The pattern I’m describing, where an OAuth grant is used to access an account, read sensitive data from email and Drive, and use that access to move past the workspace, doesn’t only describe what attackers do. It increasingly describes what AI agents do, by design, every day."
https://www.helpnetsecurity.com/2026/09/16/material-google-workspace-attack-chains/ - MSPs Say Nearly Half Their Customers Rely On Them For CISO Services
"MSPs estimate that 46% of their customers, on average, look to them to act as CISOs, according to Sophos. Most of those providers do that job without the full set of compliance services, and many spread the work across several tools. Most providers expect this work to grow. For many of those customers, the MSP is the closest thing they have to a security leader."
https://www.helpnetsecurity.com/2026/09/16/msp-ciso-services-compliance/ - Cyber-Attacks Cost Organizations $52,000 On Average
"Nearly a third (29%) of organizations globally have been hit by at least one successful cyber-attack in the past 12 months, with incidents having substantial financial, operational and human impacts on victims. The Hiscox Cyber Readiness Report 2026 found that those affected by cyber-attacks reported an average of four incidents over the period. UK-based firms were most likely to experience an incident, with successful attacks reported by 38% of organizations. US organizations were least likely to experience an attack, at 20%."
https://www.infosecurity-magazine.com/news/cyberattacks-cost-organizations/ - Major Cyber Threat Detection Vendors Shift From MITRE To UK Testing Program
"UK-based security testing and advisory provider SE Labs is launching a new testing program to help buyers evaluate cybersecurity vendors – and has attracted some prestigious names. The six-month testing program, called PIVOT, was unveiled by SE Labs on September 15. It will evaluate how effectively cybersecurity vendors can defend against the world’s most dangerous hacking groups and attack techniques."
https://www.infosecurity-magazine.com/news/cyber-vendors-mitre-uk-testing/ - Mythos Has Made 2026 Patching Hell. It Might Make 2027 a Breeze
"When Microsoft delivered over 970 patches last week, many saw a nightmare for beleaguered security staff. Gartner research vice president Craig Lawson thinks infosec workers might soon see sunlit uplands as their workloads ease. Lawson outlined that scenario at Gartner’s IT Symposium in Australia today and explained it by theorising that the increased volume of vulnerability discoveries made possible by Anthropic’s Mythos and other bug-hunting AI might be getting close to finding most of the flaws in established codebases."
https://www.theregister.com/security/2026/09/16/mythos-has-made-2026-patching-hell-it-might-make-2027-a-breeze/5296747 - Threat Intelligence Alone Won't Close The Exploitation Gap
"A leaked credential shows up in a criminal marketplace, or a vulnerability gets a disclosure advisory, and either one can be weaponized against a real target before most security teams have triaged the alert. Attackers are combining that kind of intelligence with AI-assisted exploitation to accelerate the path from exposure to breach faster than most security programs are built to react. Intelligence is still the earliest signal defenders get, and a leaked credential turning up in a feed is proof of how useful that signal has become. The problem sits one step later, in what happens after the signal arrives."
https://thehackernews.com/2026/09/threat-intelligence-alone-wont-close.html - Using Cyber Decoys To Strengthen Detection And Response
"CISA developed this guidance to help defensive teams at varying levels of cybersecurity maturity plan and implement cyber decoy strategies that strengthen their detection and response capabilities. Many organizations struggle to detect adversaries who use legitimate credentials, native tools, and living off the land (LOTL) techniques to conduct discovery, move laterally, and access data. Cyber decoys are assets that appear to be legitimate systems, accounts, or data, but are designed to distract adversaries, detect their presence, or facilitate collection of cyber threat intelligence (CTI). As organizations adopt Zero Trust models, they should assume that a malicious threat actor may gain some level of access to their environment and plan accordingly."
https://www.cisa.gov/resources-tools/resources/using-cyber-decoys-strengthen-detection-and-response
https://www.cisa.gov/sites/default/files/2026-09/using-cyber-decoys-to-strengthen-detection-and-response_508c.pdf
https://cyberscoop.com/cisa-guidance-cyber-decoys-critical-infrastructure/ - Spain's Data Agency Gets First Report Of AI-Powered Data Breach
"The Spanish Data Protection Agency (AEPD) was notified of an attack allegedly carried out with an AI agent powered by a known large language model (LLM). The organization reporting the incident said that the AI agent searched for flaws, logged into their systems, and then probed apps for additional security issues. In the final stages of the attack, the agent modified personal data and accessed financial documents. Although the Spanish agency has yet to investigate the incident and verify the information, the AEPD says the notification shows AI-related data breaches are no longer merely theoretical."
https://www.bleepingcomputer.com/news/security/spains-data-agency-gets-first-report-of-ai-powered-data-breach/
https://www.securityweek.com/first-agentic-ai-data-breach-reported-to-spanish-regulator/ - AI Security Spending Jumps As Fear Outpaces Proof Of Value
"Organizations are pouring more money into AI for cybersecurity without waiting for clear evidence of what they might be getting in return. Multiple factors are driving the spending trend. These include the rapid shift of AI from experimentation into production, the growing use of AI by attackers to automate and accelerate their operations, and in some cases, fear of being left behind as other organizations race to adopt the technology."
https://www.darkreading.com/cybersecurity-operations/ai-security-spending-jumps-fear-outpaces-proof-value
https://hs-50428896.f.hubspotemail.net/hubfs/50428896/2026 Security Budget Benchmark Report Budget Snapshot Version 09142026.pdf
อ้างอิง
Electronic Transactions Development Agency (ETDA)
- Digital Watchdog VMAX DVR And NVR Product Lineups