Find notable cyber news and cases, enriched with sources, timelines, and signals.

Recent notable Happenings and Cases

Hide ▲
Last updated: 08:26 11/09/2026 UTC
  • Case Case score 89 UNC3569 Exploitation and Remediation of Sogou Input Method on Windows Tencent/Gen Digital tied Sogou Input Method on Windows to a link-handler code-execution flaw (CVE-2026-51990) exploited in live intrusions to deploy GRAYRABBIT, and reported fixes in version 16.3.0.3498 advance defenders’ patching timelines despite unclear full exposure scope.
  • Malware Activity H score 89 GRAYRABBIT backdoor deployment via Sogou Input Method exploit Gen Digital’s GRAYRABBIT intrusion-chain writeup shows UNC3569 used a crafted sgbiz: link and follow-on staged payloads to achieve remote shell and file transfer, sharpening detection and mitigation around the whole delivery path.
  • Incident H score 73 IDScan hit by cyberattack IDScan disclosed an unauthorized-access incident impacting its IDScan.net cloud where customer records could include full names and government IDs, moving the issue from suspicion to customer-protective actions like monitoring and notifications.
  • Data Leak H score 68 AdaptHealth 4.1 million-person data exposure AdaptHealth’s disclosure that a June 5 social-engineering compromise may have exposed 4.1 million people materially increases healthcare identity-theft risk and expands urgency for remediation and enrollment guidance.
  • Advisory/Mitigation H score 58 CISA mitigation guidance for CISA Adds Cisco Secure FMC CVE-2026-20079 to KEV Sets Sept. 12 Deadline CISA added Cisco Secure FMC CVE-2026-20079 to KEV with a September 12 FCEB patch deadline after Cisco said the authentication-bypass flaw is actively exploited for root access, accelerating prioritization for exposed networks.
  • Security Patch Release H score 40 Google security patch release for CVE-2026-87491 Google’s Chrome update for CVE-2026-87491—described as an actively exploited V8 sandbox escape enabling remote code execution—pushes immediate browser patching as a highest-risk user-action step.
Last updated: 14:28 10/09/2026 UTC
  • Data Leak H score 82 IDScan identity-document data leak Multiple lawsuits were filed in Louisiana and the FBI opened an investigation into an alleged IDScan breach, advancing the case beyond reporting by moving it toward formal enforcement and scrutiny.
  • Data Leak H score 74 Vietnam-linked APIS database exposure of 220 million traveler records Kinryū Labs found a publicly accessible Elasticsearch cluster tied to a Vietnam-linked APIS environment holding 220M+ traveler records, raising the likelihood of broad identity and privacy exposure even after access was closed.
  • Data Leak H score 68 AdaptHealth 4.1 million-person data exposure AdaptHealth confirmed a June 5 social-engineering compromise may have exposed 4.1M people, expanding the incident’s impact in healthcare from an individual event to a major-scale privacy breach.
  • Data Leak H score 66 Telegram-posted 7 GB infostealer dump exposing AI tokens and PII Okta analysis of a 7GB Telegram infostealer dump found replayable, unexpired AI and cloud authentication tokens and still-valid API keys, increasing the probability of immediate account takeovers.
  • Campaign H score 66 DoppelCart 119,000-domain fake-shop fraud campaign The DoppelCart fake-shop fraud operation expanded to 119,000+ domains with 105,000+ still active, showing the campaign’s ongoing scaling and persistence in ongoing consumer-card theft.
  • Vulnerability H score 56 N-central pre-auth RCE flaw (CVE-2026-86218) CISA added CVE-2026-86218 for N-able N-central to the KEV catalog with a federal remediation deadline after N-able reported exploitation in the wild, moving it into an urgent patch-and-stop band.

Latest updates

Browse →

UK and US Microsoft 365 AI rollout outpaces permissions review

Trend

Updated: 11.09.2026 12:30 · First: 11.09.2026 12:30 · 📰 1 src / 1 articles · H score: 26

UK and US organizations are deploying Copilot and other Microsoft 365 AI tools faster than they are reviewing permissions, widening exposure to broadly shared content. Only 43% completed a thorough oversharing review before rollout, while 91% say they can see active agents and their reach. Access governance is even thinner for agent controls: just 22% have a formal policy, and 9% let an agent inherit the deployer's full permissions. The pattern leaves sensitive SharePoint and file content reachable through AI surfaces that inherit existing access.

Midnight Blizzard Claude-assisted cyberespionage campaign

Campaign

Updated: 11.09.2026 11:47 · First: 11.09.2026 11:47 · 📰 1 src / 1 articles · H score: 19

Midnight Blizzard ran a Claude-assisted cyberespionage campaign that automated malware evasion and kept the operation active across more than 20 organizations. The activity reached government ministries, defense and intelligence bodies, embassies, and think tanks across Europe, the Middle East, and Asia. Anthropic said it disrupted the campaign after tracking it from December 2025 to August 2026 and used the findings to strengthen its safeguards.

Brevo-abused Trezor security-alert phishing campaign

Campaign

Updated: 11.09.2026 10:55 · First: 11.09.2026 10:55 · 📰 1 src / 1 articles · H score: 45

A Brevo-abused phishing campaign targeted Trezor newsletter subscribers with fake security-alert emails, reaching 347,000 email addresses and driving 2,500 clicks before takedown.

Sogou Input Method Windows link-handler code-execution flaw (CVE-2026-51990)

Vulnerability

Updated: 11.09.2026 10:14 · First: 11.09.2026 10:14 · 📰 1 src / 1 articles · H score: 89

Sogou Input Method on Windows had a link-handler flaw in the `sgbiz:` path that let attacker-controlled arguments and browser navigation reach code execution under the logged-in user's privileges. Gen Digital tied the bug to CVE-2026-51990 and said Tencent completed a fix for version 16.3.0.3498 in April 2026. The flaw was used in a live intrusion to deliver the GRAYRABBIT backdoor. The patch closed the link-handler entry point, but the broader browser-engine weaknesses in the product were not removed.

GRAYRABBIT backdoor deployment via Sogou Input Method exploit

Malware Activity

Updated: 11.09.2026 10:14 · First: 11.09.2026 10:14 · 📰 1 src / 1 articles · H score: 89

The GRAYRABBIT backdoor was deployed in a live intrusion against Sogou Input Method users, giving attackers a remote command shell and the ability to stage additional modules. The payload turned a Windows exploit chain into persistent attacker access on victim machines. The backdoor traffic was tied to mail.uaiubifas[.]top on port 443, raising monitoring value for defenders.

UNC3569 Sogou Input Method exploitation campaign

Campaign

Updated: 11.09.2026 10:14 · First: 11.09.2026 10:14 · 📰 1 src / 1 articles · H score: 89

The UNC3569 campaign abused a crafted sgbiz: link to exploit Sogou Input Method on Windows, giving the operator code execution and a foothold for the GRAYRABBIT backdoor. The chain let the attacker act with the logged-in user's privileges, turning a link click into remote access. Gen Digital linked the activity to a live intrusion and said UNC3569 has targeted government, education, technology, and finance sectors in East and Southeast Asia since 2021. Tencent fixed the flaw in April 2026 and pushed version 16.3.0.3498 to close the link-handler path.

UNC3569 Exploitation and Remediation of Sogou Input Method on Windows

Case

Updated: 11.09.2026 10:14 · First: 11.09.2026 10:14 · 📰 0 src / 2 articles

Sogou Input Method on Windows was exploited through a crafted sgbiz: link that reached CVE-2026-51990, giving attackers code execution with the logged-in user's privileges and leading to GRAYRABBIT installation. The same intrusion chain also used CVE-2021-38003 in the product's Chromium-based browser path, and available material ties the operation to UNC3569. The flaw was reported to Tencent in April 2026, and the vendor said a fix was completed in version 16.3.0.3498 and pushed through automatic update. Public details still leave open the full affected-version range and whether broader browser-engine weaknesses inside the product create additional exposure beyond the closed link-handler path.

PaperCut NG and MF auth-bypass RCE chain (multiple vulnerabilities)

Vulnerability

Updated: 28.08.2026 20:12 · First: 28.08.2026 20:12 · 📰 2 src / 6 articles · H score: 53

PaperCut NG/MF vulnerability activity now includes active exploitation of CVE-2026-81578 and CVE-2026-82078, an authentication bypass and remote code execution chain affecting exposed instances. PaperCut issued a second emergency patch and told operators to remove public internet exposure and restrict PaperCut Application Server access to trusted IPs or a VPN. The latest reporting says a suspected Russian-speaking actor used OpenAI Codex and a DeepSeek model to research, validate, and deploy exploits, then compromised at least 440 instances across 395 victim organizations in 48 countries, with education-sector victims in the U.S., the U.K., France, Spain, Canada, Belgium, Portugal, Australia, Germany, and Switzerland. Earlier observed post-exploitation activity included a Java `.class` file, Base64-encoded commands, and commands such as `whoami & ver & tasklist` on a PaperCut target.

Mantax Otax Android malware activity

Malware Activity

Updated: 11.09.2026 00:40 · First: 11.09.2026 00:40 · 📰 1 src / 1 articles · H score: 32

The Mantax Otax Android malware now combines ransomware and spyware features, putting older Android devices at risk of file encryption, data theft, and harassment. It spreads through malicious APKs outside Google Play and uses phishing and social engineering to push installation, then requests Accessibility permission for deep device control. The malware pulls its C2 from GitHub, can issue commands through Firebase or WebSockets, and is already detected and blocked on up-to-date devices with active Play Protect.

Windows Server Remote Desktop Services disruption after September 2026 cumulative updates

Service Disruption

Updated: 10.09.2026 23:34 · First: 10.09.2026 23:34 · 📰 1 src / 1 articles · H score: 0

Windows Server Remote Desktop Services is experiencing a service disruption after the September 2026 cumulative updates, leaving some systems unable to accept new connections and causing sessions to hang. The affected scope includes Windows Server 2019, 2022, and 2025 installations, and some administrators report that only a hard reset restores functionality. Rolling back the update has restored service for some environments, but that also removes the month's security fixes.

Surfshark hit by cyberattack

Incident

Updated: 10.09.2026 22:15 · First: 10.09.2026 22:15 · 📰 1 src / 1 articles · H score: 10

Surfshark confirmed a breach of internal systems after a configuration error exposed an internal test server to the internet, creating risk for its engineering environment even though customer data was not impacted. The exposure also reached a separate proxy server used for content-accessibility optimization, and the accessed environment held service configurations and build-related credentials. The company detected suspicious activity on August 31, contained it on September 2, and finished remediation three days later.

Google security patch release for CVE-2026-28662

Security Patch Release

Updated: 10.09.2026 20:47 · First: 10.09.2026 20:47 · 📰 1 src / 1 articles · H score: 39

Google released the September 2026 Android security updates to patch 200 vulnerabilities across Android, including CVE-2026-28662. The bundle contains critical and high-severity flaws, and at least one issue can enable remote code execution without user interaction. Organizations running Android devices need to deploy the updates quickly to close the exposure window.

Singapore police arrest two suspects in Singpass compromise scheme

Law Enforcement

Updated: 10.09.2026 20:47 · First: 10.09.2026 20:47 · 📰 1 src / 1 articles · H score: 46

Singapore police arrested two male Chinese Malaysians in a Singpass compromise scheme, linking the case to more than 170 accounts and over 160 LiquidPay registrations. Investigators said the suspects were mobile phone shop employees who allegedly used customer interactions to reach account details. The arrests disrupt a fraud-and-account-takeover operation affecting Singapore citizens and work permit holders.

Chinese-speaking operator AI-orchestrated intrusion campaign targeting government and financial systems

Campaign

Updated: 10.09.2026 20:47 · First: 10.09.2026 20:47 · 📰 1 src / 1 articles · H score: 48

A Chinese-speaking operator is running an AI-orchestrated intrusion campaign that automates attacks against government and financial systems across multiple countries. The operation uses Anthropic Claude Code, Alibaba Qwen, DeepSeek, and SecFlow to divide reconnaissance, exploitation, collection, and reporting across specialist agents. Named targets include systems in Afghanistan, Thailand, Taiwan, the U.S., Indonesia, mainland China, and Vietnam. The task-splitting workflow and repeated intrusion chain point to an active, scalable campaign rather than isolated probing.

Cyclops Blink deployed on compromised Cisco FMC devices

Malware Activity

Updated: 10.09.2026 18:43 · First: 10.09.2026 18:43 · 📰 1 src / 1 articles · H score: 32

A Cyclops Blink variant was deployed on compromised Cisco Secure Firewall Management Center (FMC) devices, giving attackers a persistent backdoor with credential theft and network sniffing capability. The malware activity was tied to the UAT-11823 intrusion cluster and followed earlier access to the management appliances. The payload adds post-compromise control on a security-management platform that can expose internal credentials and traffic.

IDScan identity-document data leak

Data Leak

Updated: 04.09.2026 19:56 · First: 04.09.2026 19:56 · 📰 1 src / 2 articles · H score: 84

A reported IDScan data leak exposed or offered for sale more than 153 million driver’s license scans, putting large volumes of identity documents at risk. The cache was advertised by the dark-web service Nexus, and sample checks tied the material back to IDScan. The exposure increases the risk of identity theft, impersonation, and fraud for people whose IDs were scanned through businesses using the service.

IDScan hit by cyberattack

Incident

Updated: 10.09.2026 17:55 · First: 10.09.2026 17:55 · 📰 1 src / 1 articles · H score: 73

IDScan confirmed an unauthorized-access incident affecting its IDScan.net cloud after learning on or around September 1 that customer data may have been accessed or copied. The event is significant because exposed records can include full names and government-issued identification numbers, and reporting tied the breach to claims involving more than 153 million driver's license scans. IDScan said it is investigating, securing systems, and providing free credit monitoring and identity protection services.

Hagaseca Android RAT spread via THost9 loader and ADB worm behavior

Malware Activity

Updated: 10.09.2026 17:36 · First: 10.09.2026 17:36 · 📰 1 src / 1 articles · H score: 19

The Hagaseca Android remote access trojan is being spread through the THost9 loader and a worm component that scans exposed ADB services, enabling persistent device control and expanding infection reach. The malware can maintain access through shell execution, file transfers, tunneling, and downloadable modules. That combination increases the risk of broader Android compromise and harder-to-remove footholds.

StreamRat Android banking trojan with remote-control capabilities

Malware Activity

Updated: 02.09.2026 15:22 · First: 02.09.2026 15:22 · 📰 1 src / 2 articles · H score: 42

StreamRat is an Android banking trojan promoted through a fake television-streaming campaign on Meta that targeted Spanish-speaking users in Spain and reached an estimated 570,950 Meta accounts in the European Union. The lure used a crafted website and a sideloaded APK, then pushed intrusive permissions so the malware could gain Accessibility access and connect to command-and-control infrastructure. Once installed, StreamRat could capture keystrokes, show credential-stealing overlays, take screenshots, and remotely control infected devices. The same reporting also links StreamRat to TikTok-driven counterfeit streaming lures and to activity that abused Android accessibility and the MediaProjection API to harvest sensitive data.

Google Chrome V8 type confusion security flaw (CVE-2026-85046)

Vulnerability

Updated: 04.09.2026 10:18 · First: 04.09.2026 10:18 · 📰 2 src / 4 articles · H score: 36

CVE-2026-85046 is a Google Chrome V8 type-confusion vulnerability that was exploited in the wild before Google shipped fixes in 152.0.7977.82/.83 for Windows and Apple macOS and 152.0.7977.82 for Linux. The flaw was reported on August 4, 2026 by Salvatore Gulizia (aka Serotav) and can be triggered through a crafted HTML page. On September 9, 2026, Proofpoint described BlueMoon, a shared modular exploit kit, chaining CVE-2026-85046 with CVE-2026-87491 and CVE-2026-85880 to deliver Chrome remote code execution, sandbox escape, and Windows local privilege escalation. Proofpoint and Volexity linked BlueMoon deployments to JungleBamboo / APT31 and UTA0560, with activity observed since August 28 and September 1st.

Google Chrome V8 out-of-bounds write security flaw (CVE-2026-87491)

Vulnerability

Updated: 09.09.2026 12:11 · First: 09.09.2026 12:11 · 📰 2 src / 2 articles · H score: 35

CVE-2026-87491 is a V8 vulnerability in Google Chrome that can let a remote attacker execute code inside the browser sandbox through a crafted HTML page. Google shipped fixes in Chrome 153.0.8010.36/.37 for Windows and macOS, and 153.0.8010.36 for Linux, and said an exploit exists in the wild. Researchers then tied the flaw to the BlueMoon exploit kit, which combined CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880 for Chrome remote code execution, sandbox escape, and Windows local privilege escalation in separate spearphishing operations.

BlueMoon exploit kit deployment across espionage clusters

Malware Activity

Updated: 09.09.2026 19:34 · First: 09.09.2026 19:34 · 📰 2 src / 2 articles · H score: 34

BlueMoon is a shared exploit kit used by multiple cyber-espionage groups to chain Google Chrome and Microsoft Windows flaws into code execution, sandbox escape, and local privilege escalation. Proofpoint and Volexity said the activity has been observed since August 28 and September 1st, including campaigns tied to JungleBamboo / APT31 and UTA0560. The kit chains CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880, and the observed follow-on behavior includes operator-selected commands that typically use `curl` to save and run a loader. The activity expanded across distinct clusters targeting NGOs and other organizations, increasing the likelihood of broader reuse before browser updates fully propagate.

Identity-targeted malicious activity accounted for roughly half of confirmed investigations across customer environments in May-July 2026

Trend

Updated: 10.09.2026 17:00 · First: 10.09.2026 17:00 · 📰 1 src / 1 articles · H score: 31

Across May 1 to July 31, 2026, identity was the target in roughly half of confirmed malicious activity across customer environments, showing that account takeover remained a dominant attack pattern. The quarter’s findings point to repeated abuse of sessions, credentials, and phishing rather than isolated one-off intrusions. Attackers most often succeeded when they stole an already-authenticated session or used other techniques that bypassed standard login checks. The concentration of identity abuse increased operational risk because stolen access often survived password resets and even account disablement.

CISA updates Insider Threat Mitigation Guide

Public Sector Action

Updated: 10.09.2026 17:00 · First: 10.09.2026 17:00 · 📰 1 src / 1 articles · H score: 24

CISA updated its Insider Threat Mitigation Guide on September 9, 2026, expanding government guidance for organizations facing hybrid work, remote work, AI misuse, and adverse employee separations. The revision broadens practical coverage for access control and visitor screening across both physical and digital access. It gives security and HR teams updated material for reducing insider-risk exposure in a critical infrastructure context.

MantaxOtax Android malware with ransomware and spyware control

Malware Activity

Updated: 10.09.2026 16:00 · First: 10.09.2026 16:00 · 📰 1 src / 1 articles · H score: 32

The MantaxOtax Android malware now combines file encryption with spyware-style surveillance, putting infected phones at risk of both lockout and data theft. It can steal messages, credentials, and device data while also restricting access to the handset. The malware asks for device administrator rights, SMS access, and Android Accessibility, which expands control over the device. Its GitHub-resolved C2 and added screen locking and application blocking make containment and recovery more difficult.

Check Point VPN certificate mitigation guidance

Advisory/Mitigation

Updated: 10.09.2026 14:45 · First: 10.09.2026 14:45 · 📰 1 src / 1 articles · H score: 53

Check Point directed affected customers to Live Patch or the latest Jumbo Hotfix for its VPN certificate flaws, with rollout beginning on September 9. The guidance matters because some deployments could not patch immediately and had to rely on mitigation steps instead.

Check Point Security Gateways and Security Management Server VPN certificate flaws (multiple vulnerabilities)

Vulnerability

Updated: 10.09.2026 14:45 · First: 10.09.2026 14:45 · 📰 1 src / 1 articles · H score: 53

Check Point Security Gateways and Security Management Server are affected by two critical VPN certificate flaws, CVE-2026-85102 and CVE-2026-85103, that can let an unauthenticated remote attacker execute code under specific conditions. Check Point disclosed the issues on September 9 and began delivering fixes the same day. The company says it has no indication of exploitation.

Check Point VPN certificate security patch release (CVE-2026-85102, CVE-2026-85103)

Security Patch Release

Updated: 10.09.2026 14:45 · First: 10.09.2026 14:45 · 📰 1 src / 1 articles · H score: 53

Check Point began delivering fixes on September 9 for CVE-2026-85102 and CVE-2026-85103, two critical VPN certificate flaws in Security Gateways and Security Management Server. The release addresses unauthenticated remote code execution risk and gives customers remediation through Check Point Live Patch or the latest Jumbo Hotfix. Affected deployments include R82.10 / Jumbo Hotfix Take 43 or below, R82 / Take 125 or below, and R81.20 / Take 165 or below. Check Point says it found both issues itself and has no indication of attack use.

AdaptHealth 4.1 million-person data exposure

Data Leak

Updated: 10.09.2026 00:30 · First: 10.09.2026 00:30 · 📰 2 src / 2 articles · H score: 68

AdaptHealth confirmed that 4.1 million people were exposed in a June 5 cyberattack, turning the breach into a large-scale healthcare data leak. The compromise hit cloud-based business applications and patient systems after a social engineering attack took over a third-party contractor privileged account. Exposed data may include full names, contact information, health insurance information, and health information. The company said it found no evidence of identity theft or fraud and offered affected people 12 months of credit monitoring and identity protection.

US Secret Service freezes Xinbi-linked cryptoassets

Law Enforcement

Updated: 10.09.2026 11:00 · First: 10.09.2026 11:00 · 📰 1 src / 1 articles · H score: 29

The US Secret Service identified and froze $52.8m in cryptoassets linked to Xinbi Guarantee, disrupting funds tied to a major fraud marketplace. The action came alongside sanctions pressure on the platform and its support network. It increases the operational risk for users and merchants who relied on the marketplace’s wallets and payment rails.