Find notable cyber news and cases, enriched with sources, timelines, and signals.

Recent notable Happenings and Cases

Hide ▲
Last updated: 02:35 13/09/2026 UTC
Last updated: 12:50 12/09/2026 UTC
  • Case Case score 89 UNC3569 Exploitation and Remediation of Sogou Input Method on Windows Sogou Input Method on Windows had a crafted sgbiz: link-handler flaw (CVE-2026-51990) tied to UNC3569 live intrusions deploying GRAYRABBIT, with Gen Digital saying Tencent finished a fix in version 16.3.0.3498 (patching closes the entry but broader browser-engine weaknesses remain unclear).
  • Malware Activity H score 89 GRAYRABBIT backdoor deployment via Sogou Input Method exploit Gen Digital detailed UNC3569’s GRAYRABBIT intrusion chain against Sogou Input Method, showing exploit-to-backdoor delivery with remote-shell and file-transfer capability and tying activity to mail.uaiubifas[.]top:443 for detection.
  • Advisory/Mitigation H score 58 CISA mitigation guidance for CISA Adds Cisco Secure FMC CVE-2026-20079 to KEV Sets Sept. 12 Deadline CISA added Cisco Secure FMC authentication-bypass flaw CVE-2026-20079 to KEV with an FCEB patch deadline of September 12, warning it is actively exploited and can lead to unauthenticated remote script execution and root access with no workarounds.
  • Incident H score 73 IDScan hit by cyberattack IDScan reported that an unauthorized third party may have accessed or copied data in its IDScan.net cloud, potentially including driver-license identifiers for a breach linked to claims involving 153+ million scans.
  • Vulnerability H score 56 N-central pre-auth RCE flaw (CVE-2026-86218) CISA added N-able N-central pre-auth RCE flaw CVE-2026-86218 to KEV after N-able said it has been observed being exploited in the wild, accelerating remediation priority for unpatched on-prem instances.
  • Exploitation Wave H score 42 JFrog Artifactory CVE-2026-42018/CVE-2026-42016 exploitation wave Wiz reported an Artifactory exploitation wave using CVE-2026-42018/CVE-2026-42016 to bypass authentication, mint admin-scoped tokens, and deploy a Rust backdoor, with some compromises creating administrators in under five minutes.

Latest updates

Browse →

Check Point VPN certificate security patch release (CVE-2026-85102, CVE-2026-85103)

Security Patch Release

Updated: 10.09.2026 14:45 · First: 10.09.2026 14:45 · 📰 2 src / 2 articles · H score: 53

Check Point began delivering fixes on September 9 for CVE-2026-85102 and CVE-2026-85103, two critical VPN certificate flaws in Security Gateways and Security Management Server. The release addresses unauthenticated remote code execution risk and gives customers remediation through Check Point Live Patch or the latest Jumbo Hotfix. Affected deployments include R82.10 / Jumbo Hotfix Take 43 or below, R82 / Take 125 or below, and R81.20 / Take 165 or below. Check Point says it found both issues itself and has no indication of attack use.

AI brand-name phishing campaign across multiple customers

Campaign

Updated: 12.09.2026 13:24 · First: 12.09.2026 13:24 · 📰 1 src / 1 articles · H score: 34

The AI-themed phishing campaign used familiar AI brand names as lures and was observed across multiple customers during the study window. The emails relied on subject lines featuring the biggest names in AI, turning routine product familiarity into a phishing pretext. The operation mattered because it showed a distinct attack thread separate from the broader noise of legitimate AI activity.

SOC guidance to tune AI-agent detections and hunt exposure paths

Defensive Guidance

Updated: 12.09.2026 13:24 · First: 12.09.2026 13:24 · 📰 1 src / 1 articles · H score: 11

SOC teams using AI tools and agents are being told to tune legacy detections and hunt risky AI activity because routine agent work is flooding alert queues while exposing real credential and data-risk paths. The guidance focuses on reducing false positives without missing permission-bypass flags, unauthorized tunnels, and risky OAuth grants. It also pushes teams to limit what can be shared with third-party AI platforms and to isolate agent workloads to shrink blast radius.

Rising AI-related alert volume is reshaping enterprise SOC triage

Trend

Updated: 12.09.2026 13:24 · First: 12.09.2026 13:24 · 📰 1 src / 1 articles · H score: 28

Enterprise SOCs are seeing a fast-rising stream of AI-related alerts, and the trend is increasing triage burden even though it remains a small share of total volume. The measured slice reached 0.43% of SOC alerts and climbed 685% between February and June 2026. Most of the new activity is noise, but the growth is large enough to bury the small set of genuine exposures.

OpenAI agents' GemStuffer RubyGems exfiltration campaign

Campaign

Updated: 12.09.2026 12:07 · First: 12.09.2026 12:07 · 📰 1 src / 1 articles · H score: 43

The GemStuffer campaign tied to OpenAI agents expanded across RubyGems in May-June 2026, using repeated package publishing and documentation-build abuse to move data off-platform and reach RubyDoc.info servers. The operation matters because it combined coordinated package submissions, public-data scraping, and API-key theft attempts into a persistent multi-stage abuse pattern. It also touched multiple bursts of activity, showing more than a one-off upload spree.

RubyDoc.info hit by network compromise

Incident

Updated: 12.09.2026 12:07 · First: 12.09.2026 12:07 · 📰 1 src / 1 articles · H score: 32

RubyDoc.info suffered a package-triggered compromise that enabled arbitrary remote code execution on its servers and let attackers scrape and stage data through the documentation build path. The abuse ran during May-June 2026 and turned a trusted build workflow into an execution foothold. The resulting access increased the risk of unauthorized data handling and further abuse of the service.

RubyDoc.info .yardopts build-process RCE flaw (actively exploited)

Vulnerability

Updated: 12.09.2026 12:07 · First: 12.09.2026 12:07 · 📰 1 src / 1 articles · H score: 38

RubyDoc.info's documentation build process was abused through a .yardopts design quirk, enabling arbitrary remote code execution on build servers. The flaw let attackers turn gem documentation requests into code execution and exfiltrate public data from U.K. government websites. The abuse was observed during May-June 2026 and affected the service that builds documentation for submitted gems.

ShinyHunters and Helix passkey-themed Microsoft 365 account compromise campaign

Campaign

Updated: 11.09.2026 20:26 · First: 11.09.2026 20:26 · 📰 1 src / 1 articles · H score: 34

A ShinyHunters- and Helix-linked campaign is using passkey and SSO-themed social engineering to compromise corporate Microsoft accounts, exposing Microsoft 365 data and connected cloud access across multiple organizations. The operation has been active since May 2026 and relies on phone and message lures that impersonate IT help desks. Victims are steered to fake Microsoft login pages, AiTM phishing, or device-code abuse to capture credentials and session tokens. Compromised identities are then used for cloud reconnaissance and data theft.

JFrog Artifactory CVE-2026-42018/CVE-2026-42016 exploitation wave

Exploitation Wave

Updated: 11.09.2026 19:29 · First: 11.09.2026 19:29 · 📰 2 src / 2 articles · H score: 56

JFrog Artifactory is in an active exploitation wave involving CVE-2026-42018 and CVE-2026-42016, where attackers used the flaws to move from low-privilege access to administrator control on self-hosted Artifactory systems between August 15 and September 8, 2026. The activity includes rapid token abuse and account creation across multiple environments, and Wiz says attackers also chained CVE-2026-82329 to take admin control and deploy backdoors. CISA has since added the Artifactory flaws to its KEV catalog after reports of active exploitation. Related reports also describe post-exploitation use of malicious Groovy plugins, Rust-based backdoors, and compromise of vulnerable instances.

JFrog Artifactory authentication bypass and token validation flaws (multiple vulnerabilities)

Vulnerability

Updated: 11.09.2026 19:29 · First: 11.09.2026 19:29 · 📰 2 src / 2 articles · H score: 56

JFrog Artifactory flaws CVE-2026-42018 and CVE-2026-42016 were tied to active exploitation against self-hosted servers, with attackers chaining them to bypass authentication, steal JWTs, and reach admin-level access. The exploitation was observed between August 15 and September 8, 2026, and related activity also involved CVE-2026-82329 for administrator-token abuse. CISA later added the Artifactory flaws to its KEV catalog, and defenders were urged to upgrade immediately and hunt for rogue accounts, token creation, and suspicious plugin activity.

JFrog Artifactory custom Rust backdoor deployment

Malware Activity

Updated: 11.09.2026 19:29 · First: 11.09.2026 19:29 · 📰 1 src / 1 articles · H score: 34

A custom Rust backdoor was dropped on compromised JFrog Artifactory servers, giving attackers C2-enabled remote control and persistence. The malware was deployed after intruders obtained administrative access, making the compromise more durable and harder to evict. The activity affected self-hosted Artifactory instances during the observed intrusion window from August 15 to September 8, 2026.

China-based AI labs illicit Claude distillation campaign

Campaign

Updated: 11.09.2026 19:15 · First: 11.09.2026 19:15 · 📰 1 src / 1 articles · H score: 27

A coordinated industrial-scale distillation campaign against Claude is extracting reasoning and tool-use outputs to train competing models, increasing the risk of unauthorized capability transfer at massive scale. The operation spans multiple China-based AI labs and uses fraudulent accounts, proxy services, and stolen or purchased credentials to mask access. Observed activity includes millions of exchanges and repeated waves against Claude Opus 4.6 and 4.7. The harvested transcripts include sensitive conversations and advanced reasoning traces that can be reused in follow-on training.

GTG-30006 Claude-assisted malware and phishing pipeline

Malware Activity

Updated: 11.09.2026 17:29 · First: 11.09.2026 17:29 · 📰 1 src / 1 articles · H score: 20

An Iranian actor, GTG-30006, used Claude.ai to build malware, a delivery pipeline, and a phishing portal targeting domestic Iranians, increasing the risk of credential theft and Windows implant deployment. The operation included a fake ESET NOD32 login page that sent captured credentials to Telegram, a ClickFix-style Windows Run dialog lure, and geofenced delivery pages. The actor also built SECOMS64, a modular Windows implant with keylogging, screenshot capture, and Chrome credential extraction capabilities.

Anthropic Claude misuse analysis of multi-agent reconnaissance, exploitation, and exfiltration

Technical Analysis

Updated: 11.09.2026 17:29 · First: 11.09.2026 17:29 · 📰 2 src / 2 articles · H score: 59

Anthropic says Claude AI was abused by multiple threat groups, including ShinyHunters, Midnight Blizzard, and GTG-10007, for credential harvesting, reconnaissance, phishing, malware development, exploit development, and data exfiltration. The report says the activity ran from December 2025 to August 2026 and shows AI use moving beyond prompting into multi-agent automation that executed much of the workflow. In one ShinyHunters-linked case, a pipeline on 10 AWS EC2 workers mass-downloaded 1.8 million Android APKs, scanned them with TruffleHog, and routed verified secrets to Telegram. Anthropic also says the same period included abuse to obtain 2,100+ Azure AD token sets tied to 40+ Microsoft tenants and at least 1TB of stolen data.

North African government technology authority data exposed after North African government technology authority breach

Data Leak

Updated: 11.09.2026 17:10 · First: 11.09.2026 17:10 · 📰 1 src / 1 articles · H score: 45

A North African government technology authority suffered a data leak after attackers hijacked its central account server and exfiltrated a credential database containing over 300,000 national identity records and more than half a million company registry records. The exposed data raises the risk of identity abuse, account takeover, and downstream targeting of listed people and companies. The compromise was reached through VPN appliance credentials and was attributed after the intrusion.

Microsoft 365 Direct Send phishing campaign tracked to US Eastern business hours

Campaign

Updated: 11.09.2026 16:30 · First: 11.09.2026 16:30 · 📰 1 src / 1 articles · H score: 39

A phishing campaign abused Microsoft 365 Direct Send to deliver 29,785 confirmed phishing emails across July and August 2026, with activity clustering during US Eastern business hours. The operation matters because the messages could appear to come from trusted internal senders while bypassing normal email security gateways. One observed message reached 900 recipients in a single send.

GitLab self-managed installations immediate upgrade advisory

Advisory/Mitigation

Updated: 11.09.2026 14:15 · First: 11.09.2026 14:15 · 📰 2 src / 2 articles · H score: 45

GitLab issued immediate upgrade guidance for self-managed GitLab installations after fixing two security issues in GitLab CE and GitLab EE. Operators were told to move to 19.3.2, 19.2.6, or 19.1 without delay. The guidance reduces exposure to CVE-2023-2825 and CVE-2026-87719, which can enable arbitrary file reads or sensitive credential theft under certain conditions.

GitLab repository commits API path traversal vulnerability (CVE-2023-2825)

Vulnerability

Updated: 11.09.2026 14:15 · First: 11.09.2026 14:15 · 📰 1 src / 1 articles · H score: 33

GitLab has a maximum-severity path traversal vulnerability, CVE-2023-2825, that can let unauthenticated attackers read arbitrary files from vulnerable servers under certain conditions. The flaw affects the repository commits API and exposes GitLab Community Edition (CE) and Enterprise Edition (EE) deployments until they are patched. GitLab says self-managed installations should upgrade immediately because fixed builds are now available.

GitLab CE/EE security patch release (CVE-2023-2825, CVE-2026-87719)

Security Patch Release

Updated: 11.09.2026 14:15 · First: 11.09.2026 14:15 · 📰 2 src / 2 articles · H score: 45

GitLab released fixes for CVE-2023-2825 and CVE-2026-87719 in GitLab Community Edition (CE) and Enterprise Edition (EE), requiring self-managed installations to upgrade immediately. The patch release addresses both a maximum-severity path traversal flaw and a critical insecure deserialization issue.

Microsoft Teams and Outlook for Windows launch failure on ARM-based Windows PCs

Service Disruption

Updated: 11.09.2026 12:39 · First: 11.09.2026 12:39 · 📰 1 src / 1 articles · H score: 0

Microsoft fixed a launch failure that caused Teams and the new Outlook for Windows to fail to open or close unexpectedly on ARM-based Windows devices after August 11, 2026 updates. The disruption affected Windows 11 24H2 or later systems, especially new or freshly imaged PCs that had not yet installed Microsoft Store updates. Microsoft later said the issue was resolved in KB5124012 and newer updates. The company also pointed customers to the Auto Super Resolution Package as a temporary workaround.

UK and US Microsoft 365 AI rollout outpaces permissions review

Trend

Updated: 11.09.2026 12:30 · First: 11.09.2026 12:30 · 📰 1 src / 1 articles · H score: 26

UK and US organizations are deploying Copilot and other Microsoft 365 AI tools faster than they are reviewing permissions, widening exposure to broadly shared content. Only 43% completed a thorough oversharing review before rollout, while 91% say they can see active agents and their reach. Access governance is even thinner for agent controls: just 22% have a formal policy, and 9% let an agent inherit the deployer's full permissions. The pattern leaves sensitive SharePoint and file content reachable through AI surfaces that inherit existing access.

Midnight Blizzard Claude-assisted cyberespionage campaign

Campaign

Updated: 11.09.2026 11:47 · First: 11.09.2026 11:47 · 📰 1 src / 1 articles · H score: 19

Midnight Blizzard ran a Claude-assisted cyberespionage campaign that automated malware evasion and kept the operation active across more than 20 organizations. The activity reached government ministries, defense and intelligence bodies, embassies, and think tanks across Europe, the Middle East, and Asia. Anthropic said it disrupted the campaign after tracking it from December 2025 to August 2026 and used the findings to strengthen its safeguards.

Brevo-abused Trezor security-alert phishing campaign

Campaign

Updated: 11.09.2026 10:55 · First: 11.09.2026 10:55 · 📰 1 src / 1 articles · H score: 45

A Brevo-abused phishing campaign targeted Trezor newsletter subscribers with fake security-alert emails, reaching 347,000 email addresses and driving 2,500 clicks before takedown.

Sogou Input Method Windows link-handler code-execution flaw (CVE-2026-51990)

Vulnerability

Updated: 11.09.2026 10:14 · First: 11.09.2026 10:14 · 📰 1 src / 1 articles · H score: 89

Sogou Input Method on Windows had a link-handler flaw in the `sgbiz:` path that let attacker-controlled arguments and browser navigation reach code execution under the logged-in user's privileges. Gen Digital tied the bug to CVE-2026-51990 and said Tencent completed a fix for version 16.3.0.3498 in April 2026. The flaw was used in a live intrusion to deliver the GRAYRABBIT backdoor. The patch closed the link-handler entry point, but the broader browser-engine weaknesses in the product were not removed.

GRAYRABBIT backdoor deployment via Sogou Input Method exploit

Malware Activity

Updated: 11.09.2026 10:14 · First: 11.09.2026 10:14 · 📰 1 src / 1 articles · H score: 89

The GRAYRABBIT backdoor was deployed in a live intrusion against Sogou Input Method users, giving attackers a remote command shell and the ability to stage additional modules. The payload turned a Windows exploit chain into persistent attacker access on victim machines. The backdoor traffic was tied to mail.uaiubifas[.]top on port 443, raising monitoring value for defenders.

UNC3569 Sogou Input Method exploitation campaign

Campaign

Updated: 11.09.2026 10:14 · First: 11.09.2026 10:14 · 📰 1 src / 1 articles · H score: 89

The UNC3569 campaign abused a crafted sgbiz: link to exploit Sogou Input Method on Windows, giving the operator code execution and a foothold for the GRAYRABBIT backdoor. The chain let the attacker act with the logged-in user's privileges, turning a link click into remote access. Gen Digital linked the activity to a live intrusion and said UNC3569 has targeted government, education, technology, and finance sectors in East and Southeast Asia since 2021. Tencent fixed the flaw in April 2026 and pushed version 16.3.0.3498 to close the link-handler path.

UNC3569 Exploitation and Remediation of Sogou Input Method on Windows

Case

Updated: 11.09.2026 10:14 · First: 11.09.2026 10:14 · 📰 0 src / 2 articles

Sogou Input Method on Windows was exploited through a crafted sgbiz: link that reached CVE-2026-51990, giving attackers code execution with the logged-in user's privileges and leading to GRAYRABBIT installation. The same intrusion chain also used CVE-2021-38003 in the product's Chromium-based browser path, and available material ties the operation to UNC3569. The flaw was reported to Tencent in April 2026, and the vendor said a fix was completed in version 16.3.0.3498 and pushed through automatic update. Public details still leave open the full affected-version range and whether broader browser-engine weaknesses inside the product create additional exposure beyond the closed link-handler path.

PaperCut NG and MF auth-bypass RCE chain (multiple vulnerabilities)

Vulnerability

Updated: 28.08.2026 20:12 · First: 28.08.2026 20:12 · 📰 2 src / 6 articles · H score: 53

PaperCut NG/MF vulnerability activity now includes active exploitation of CVE-2026-81578 and CVE-2026-82078, an authentication bypass and remote code execution chain affecting exposed instances. PaperCut issued a second emergency patch and told operators to remove public internet exposure and restrict PaperCut Application Server access to trusted IPs or a VPN. The latest reporting says a suspected Russian-speaking actor used OpenAI Codex and a DeepSeek model to research, validate, and deploy exploits, then compromised at least 440 instances across 395 victim organizations in 48 countries, with education-sector victims in the U.S., the U.K., France, Spain, Canada, Belgium, Portugal, Australia, Germany, and Switzerland. Earlier observed post-exploitation activity included a Java `.class` file, Base64-encoded commands, and commands such as `whoami & ver & tasklist` on a PaperCut target.

Mantax Otax Android malware activity

Malware Activity

Updated: 11.09.2026 00:40 · First: 11.09.2026 00:40 · 📰 1 src / 1 articles · H score: 32

The Mantax Otax Android malware now combines ransomware and spyware features, putting older Android devices at risk of file encryption, data theft, and harassment. It spreads through malicious APKs outside Google Play and uses phishing and social engineering to push installation, then requests Accessibility permission for deep device control. The malware pulls its C2 from GitHub, can issue commands through Firebase or WebSockets, and is already detected and blocked on up-to-date devices with active Play Protect.

Windows Server Remote Desktop Services disruption after September 2026 cumulative updates

Service Disruption

Updated: 10.09.2026 23:34 · First: 10.09.2026 23:34 · 📰 1 src / 1 articles · H score: 0

Windows Server Remote Desktop Services is experiencing a service disruption after the September 2026 cumulative updates, leaving some systems unable to accept new connections and causing sessions to hang. The affected scope includes Windows Server 2019, 2022, and 2025 installations, and some administrators report that only a hard reset restores functionality. Rolling back the update has restored service for some environments, but that also removes the month's security fixes.