Major Cyber Attacks, Data Breaches, Ransomware Attacks: September 2026

Date: 1 October 2026

Featured Image

September’s cyber incidents did not follow a neat pattern. CenterPoint Energy faced a cybersecurity incident affecting corporate systems. Incidents and reported compromises involving the Royal Belgian Table Tennis Federation (FRBTT), FBI systems, Dyfed-Powys Police, an Australian government website and Aesto Health showed how attackers continue to find opportunities across vastly different sectors. From critical infrastructure and law enforcement to healthcare and public-facing services, the month’s incidents demonstrate just how widely cyber risk can spread.

  1. Ransomware Attacks in September 2026
  2. Data Breaches in September 2026 
  3. Cyber Attacks in September 2026 
  4. New Malware and Ransomware Discovered
  5. Vulnerabilities Discovered and Patches Released 
  6. Advisories issued, reports, analysis etc. in September 2026


Data exposure was another defining theme. Condé Nast, Mathspace, Vietnam’s APIS database, Gyazo and IDScan.net all featured in September’s cyber headlines, with some incidents involving potentially significant volumes of personal or user information. Particularly notable was the reported exposure associated with Vietnam’s APIS database, involving data linked to as many as 220 million records. As always, some figures and attacker claims remain subject to investigation and should be treated as provisional until independently confirmed.

Taken together, September’s incidents reinforce the importance of preparing for more than one type of cyber crisis.

Cyber Management Alliance helps your organisation build that readiness through Cyber Incident Response Plans and Playbooks creation and review services, Cyber Tabletop Exercises, Executive Cybersecurity Training, Third-Party Risk Assessments and cyber resilience assessments. The objective is not to promise that every attack can be prevented, but to reduce exposure, identify weaknesses earlier and ensure that when an incident does occur, teams know exactly how to respond, contain the damage and recover.

Ransomware Attacks in September 2026

Date

Victim

Summary

Threat Actor

Business Impact

Source Link

September 1, 2026

Nutex Health

Ransomware gang claims Nutex Health data breach

Unknown ransomware gang

A ransomware group claimed it had breached Nutex Health and stolen sensitive company and patient data, but the company had not publicly confirmed the attackers’ claims or the full scope of the alleged breach.

Nutex Health Ransomware Attack

September 5, 2026

Berlin state government, specifically two government departments.

Berlin launches crisis response after hackers publish stolen data

Unknown ransomware group

Berlin’s state government launched a high-level crisis response after a ransomware group published stolen data from two government departments, while investigators assessed the extent of the compromise and the impact of the exposed information

Berlin State Government Attack

September 15, 2026

Organizations using vulnerable VMware vCenter Server systems.

CISA: Critical VMware RCE flaw now exploited by ransomware gangs

Unknown

Ransomware gangs exploited the critical VMware vCenter vulnerability to gain remote code execution on vulnerable systems. The flaw had already been abused by attackers to deploy a reverse SSH tool for persistence and remote access, and CISA later confirmed that ransomware actors had joined the exploitation activity, putting organizations’ networks and sensitive data at risk.

Source: Bleeping Computer

September 28, 2026 

Keio

Japan's Keio confirms ransomware attack disrupted business systems  

Unknown 

The ransomware attack disrupted Keio’s business systems, including hospitality and payment-related services, while the company shut down its network to contain the incident; railway operations were not affected, and an investigation is underway to determine whether customer or business-partner data was accessed. 

Source: Bleeping Computer 

 
 

 Back to Top 

Data Breaches in September 2026

Date

Victim

Summary

Threat Actor

Business Impact

Source Link

September 1, 2026

Aesto Health and patients of its healthcare-provider clients

Aesto Health says data breach affects over 9.5 million patients

Unknown

Aesto Health suffered a data breach after an unauthorized actor accessed a portion of its AWS infrastructure between December 2 and December 18, 2025, potentially exposing personal and protected health information belonging to 9,540,683 individuals, including names, dates of birth, medical information, health insurance details, government IDs, financial account information and Social Security numbers.

Source: Bleeping Computer

September 1, 2026



Novocure

Novocure data breach affects more than 1,400 cancer patients

ShinyHunters

Novocure suffered unauthorized access to some of its information systems in mid-August 2026, exposing internal patient ID numbers from more than 1,400 U.S. patient records, identifying information for fewer than 50 other patients, healthcare-provider contact details, and employee contact information; the company said its medical treatment devices and operations were not affected.

Source: Bleeping Computer

September 2, 2026

Dropbox users

Dropbox accounts breached through Lenovo email verification flaw

Unknown

Attackers exploited a flaw in Lenovo’s email verification process to create fraudulent Lenovo IDs and use them to access matching Dropbox accounts without passwords; around 5,000 accounts were accessed, with some users’ files viewed and downloaded.

Source: Bleeping Computer

September 5, 2026

Trezor customers

Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted

Unknown

The ShipMonk breach exposed personal and order information belonging to approximately 67,000 additional U.S. Trezor customers whose older records should have been deleted. The exposed information included names, email addresses, phone numbers, shipping addresses and order numbers, increasing the risk of phishing, scams and potential physical-security concerns.

ShipMonk Data Breach

September 5, 2026

JetBrains Cadence

Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials

Unknown

Attackers exploited an unpatched critical TeamCity vulnerability to breach JetBrains’ Cadence environment, gaining access to the Cadence server and potentially compromising AWS credentials, secrets, backups, and other credentials available to its executions. JetBrains urged Cadence users to revoke and rotate potentially exposed credentials.

JetBrains Cadence Attack

September 6, 2026

Bimbo Bakeries USA

Bimbo Bakeries USA Confirms Data Breach in Oracle EBS Zero-Day Attack

Clop

Bimbo Bakeries USA had its employee data stolen after attackers exploited an Oracle E-Business Suite zero-day through a third-party vendor, with one stolen file containing victims’ names and Social Security numbers; the company had not disclosed the total number of affected individuals.

Bimbo Bakeries Data Breach

September 7, 2026

Condé Nast

Condé Nast Data of 32.8 Million Users Offered for Sale After WIRED Leak

Unknown

A database containing data from about 32.8 million Condé Nast user accounts was offered for $15,000 on a Russian-language cybercrime forum; a sample was found to match genuine Condé Nast account data collected in 2025, although Condé Nast had not publicly confirmed the breach. The exposed information reportedly included email addresses, names, postal addresses, dates of birth and phone numbers, but no passwords or payment-card data.

Condé Nast

September 7, 2026

Microsoft 365 users and organizations, particularly executives and staff across construction, healthcare, finance, real estate, and professional services.

Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks

PREY-0058, with links to UNC6671 and activity associated with Cinder/Pink-affiliated groups.

Attackers impersonated IT help-desk staff in phone calls, tricked executives into handing over Microsoft 365 credentials and MFA approvals, stole session tokens, accessed SharePoint, OneDrive, Exchange and Box data, and then exfiltrated information for extortion

Source: thehackernews.com

September 7, 2026

Mathspace

Mathspace discloses data breach affecting over 1 million people

Unknown

Mathspace disclosed that attackers had breached its systems and stolen personal information belonging to more than 1 million students, staff, and parents.

Source: Bleeping Computer

September 8, 2026

APIS database of 220M passenger and crew records belonging to Vietnam

Massive data breach sees 220 million traveler records exposed - nine years of airline info leaked including passenger and passport details

Unknown

A misconfigured cloud database exposed around 220 million passenger and crew records, including names, passport and travel-document numbers, nationalities, birth dates, flight details, seat assignments and other travel information; the database was secured after researchers notified Vietnamese authorities and affected airlines.

Source: techradar.com

September 8, 2026

Florida Department of Highway Safety and Motor Vehicles (FLHSMV), specifically its DAVID driver-information database

ShinyHunters hackers claim breach of Florida "DAVID" DMV database

ShinyHunters

ShinyHunters claimed it had breached Florida’s DAVID DMV database and stolen more than 200,000 driver records, which it allegedly obtained from the state’s online driver-information platform. The claim involved stolen personal information, but the breach had not been independently confirmed by Florida authorities.

Source: Bleeping Computer

September 9, 2026

Veradigm Inc. and a limited group of its healthcare customers

Veradigm confirms patient data exposed in third-party data breach

Unknown

An unauthorized party used stolen credentials from a third-party vendor to access a Veradigm API and download patient information, including Social Security numbers in some cases; however, clinical data was not compromised and Veradigm’s systems and services were not disrupted.

Source: cybersecuritynews.com

September 10, 2026

IDScan and more than 150 million individuals whose driver’s license records were stored by the company

ID verification giant IDScan confirms data breach with more than 150 million driver’s licenses stolen

Unknown

Hackers stole driver’s license records from IDScan’s cloud systems, exposing names, driver’s license numbers, passport and other government-issued identity numbers, with a dark-web database reportedly providing access to more than 150 million records and photos.

Source: techcrunch.com

September 10, 2026

AdaptHealth

4.1 Million Impacted by AdaptHealth Data Breach

Unknown

AdaptHealth disclosed that an attacker had accessed its systems and stolen personal, health, and insurance information belonging to more than 4.1 million people.

Source: securityweek.com

September 10, 2026

Greenberg Traurig

Law firm Greenberg Traurig says 'limited' data posted to dark web as cyber attacks mount

Unknown

Greenberg Traurig said an unauthorized actor had accessed and posted a limited number of the firm’s documents on the dark web, affecting a small number of clients; the firm said its own systems had not been compromised, although some exposed information included Social Security details.

Source: Reuters

September 10, 2026

Weverse, the South Korean fan community platform operated by HYBE

Data breach hits Weverse, exposing confidential data of over 420,000 accounts

Unknown

Weverse confirmed that confidential information linked to 422,584 accounts had been compromised, including internal user IDs and purchase, payment-method, transaction, cancellation and refund details; the company said the exposed internal identifiers could not directly identify users or be used on their own for payment fraud.

Source: teiss.co.uk

September 12, 2026

Revolut

Revolut confirms customer data breach through fake government requests

Unknown

Revolut disclosed that an unauthorized party used fraudulent requests sent from a legitimate government agency email domain to obtain sensitive customer information, including birth dates, contact details, passport and driver’s license copies, and potentially verification selfies, account statements and transaction histories; Revolut said its systems and customer funds remained unaffected.

Source: techcrunch.com

September 12, 2026

Florida Department of Highway Safety and Motor Vehicles (FLHSMV), specifically its DAVID driver and vehicle database

Florida says motor vehicle data breach tied to credentials stolen from officer’s personal

ShinyHunters

ShinyHunters claimed access to Florida’s motor vehicle database, and FLHSMV later confirmed that a breach had occurred after attackers used credentials belonging to a Plant City police officer that had been improperly stored on the officer’s personal device; the agency said the breach was quickly contained and was no longer ongoing.

Source: The Record Media

September 14, 2026

Digital Agency, Government of Japan

Japan's Digital Agency says VPN flaw exposed 246,000 personnel records

Unknown

An attacker exploited a vulnerability in a VPN device used by Japan’s Government Solution Service to gain unauthorized access to an internal system as the incident potentially exposed around 246,000 records, including names, email addresses, telephone numbers and physical addresses.

Source: Bleeping Computer

September 16, 2026

Spain’s Data Protection Agency (AEPD)

Spain's data agency gets first report of AI-powered data breach

AI-powered autonomous agent; the specific operator or threat actor was not identified.

The AI agent reportedly identified vulnerabilities, gained access to the organization’s systems, searched applications for additional weaknesses, modified personal data and accessed financial documents, although the AEPD had not yet independently verified the incident.

Source: Bleeping Computer

September 17, 2026

Russia’s Central Election Commission and contractors involved in the Vybory election administration platform, including Rostelecom

Hackers claim breach of Russian election systems days before parliamentary vote

CikLeak

CikLeak claimed it had breached systems linked to Russia’s Central Election Commission and election-system contractors and had stolen internal documents, server configurations, passwords and employee communications; the stolen material was reportedly authenticated, although it remained unclear whether systems directly involved in voting or ballot counting had been accessed.

Source: The Record Media

September 18, 2026

Gyazo

Gyazo server flaw exploited to steal 23.6 million user records

Unknown

Attackers exploited a vulnerability in Gyazo’s image-upload server to gain unauthorized access and execute commands, stealing approximately 23.62 million user records and metadata from about 490 million images. The exposed information included names, email addresses, password hashes, user and device IDs, login-session IDs, profile details and other account data, while image metadata included IP addresses, EXIF location data, OCR text and hashed passphrases. Gyazo temporarily restricted access to some images because it could not rule out that private images had been viewed.

Source: Bleeping Computer

September 22, 2026

Federal Bureau of Investigation (FBI)

Hacking group ShinyHunters claims it breached the FBI, stole agents’ and applicants’ data

ShinyHunters

ShinyHunters claimed it breached FBI systems and stole sensitive information belonging to thousands of FBI agents and job applicants, including names, home addresses and phone numbers. The group reportedly accessed an Oracle PeopleSoft server before pivoting into an Amazon-hosted government cloud environment and claimed to have taken terabytes of data. The FBI jobs website and special-agent applicant portal were also reportedly disrupted and taken offline for maintenance. The FBI had not independently confirmed the full scope of the alleged data theft at the time of the report.

Source: techcrunch.com

September 22, 2026

BigCommerce merchants and their customers

BigCommerce merchants impacted by third-party app data breach

Unknown

Attackers compromised credentials belonging to the third-party Ribon and Ribon 1.5 applications and used them between September 13 and September 17, 2026, to access shopper data from affected BigCommerce stores and inject malicious scripts into a small number of merchant storefronts. Exposed information included customers’ names, email addresses, phone numbers and shipping addresses. BigCommerce said its own platform and systems were not breached, and passwords and payment-card information were not exposed.

BigCommerce Merchants Data Breach

September 24, 2026

Astrana

Astrana latest healthcare tech firm to report data breach to SEC

Unknown

The cyberattack gave hackers unauthorized access to Astrana’s servers, potentially exposing confidential and sensitive information and forcing the company to restore some systems from clean backups.

Source: The Record Media

September 29, 2026 

East Suffolk and North Essex NHS Foundation Trust (ESNEFT) 

10 NHS staff suspended over data breach involving Noah Woods 

 Unknown 

The data breach led to 10 NHS staff members being suspended amid an investigation into alleged unauthorised access to the medical records of Noah Woods, raising concerns over patient confidentiality and the handling of sensitive health information. 

 Source: The BBC  

September 30, 2026 

Bee Cheng Hiang 

Singapore reports first data breach linked to AI use  

Unknown 

An AI-assisted coding error at Bee Cheng Hiang exposed the email addresses of 95,364 customers through bulk marketing emails, marking Singapore’s first reported AI-related data breach, although no further misuse of the exposed information has been found. 

Source: Bloomberg.com  

September 30, 2026 

Times Car Rental 

Times Car Rental says data breach affected 6.6 million accounts 

Unknown 

The data breach affected approximately 6.6 million Times Car Rental accounts, with about 1.6 million documents accessed, including images used to verify customers’ personal information. 

Times Car Rental Data Breach 

September 30, 2026 

U.S. Department of Defense / Defense Manpower Data Center (DMDC) 

Pentagon breach exposed sensitive data on nearly 3 million people 

Unknown

A Pentagon Defense Manpower Data Center breach exposed sensitive personal information of 2.76 million living people and 294,000 deceased individuals, including Social Security numbers and military or civilian job details, although officials said there is currently no evidence the data has been misused. 

Source: abcnews.com 

 
 

Back to Top 

Cyber Attacks in September 2026

Date

Victim

Summary

Threat Actor

Business Impact

Source Link

September 2, 2026

Approximately 80,000 freelancers who used an unnamed freelance employment technology company

US charges Russian for infecting 80,000 freelancers with malware

Searzhudin Tamirlanovich Aktulaev

Aktulaev allegedly used 255 fake accounts to send malicious Excel attachments to around 80,000 freelancers between June 2016 and November 2017, infecting their devices with TVRAT and DarkVNC malware that enabled remote access and the theft of e-commerce credentials and personally identifiable information.

Source: Bleeping Computer

September 8, 2026

Springfield Public Schools and Everett City Hall, Massachusetts

Massachusetts school district, city hall shutter after cyber incidents.

Unknown

Cyber incidents disrupted essential systems at Springfield Public Schools, affecting phone lines and other services and forcing schools to close temporarily, while a separate attack disrupted Everett City Hall’s internal network and systems, leading the city to close the building to the public as officials investigated and worked to restore operations.

Source: The Record Media

September 8, 2026

Stadtwerke Landsberg, a municipal utility in Bavaria, Germany

Cyber attack encrypts systems at Bavarian municipal utility

Unknown

Hackers encrypted the utility’s central IT network, disrupting office systems and limiting staff communications, while electricity, water and other essential services continued operating; the utility also warned that customer personal and banking data might have been accessed or stolen.

Source: The Record Media

September 10, 2026

Multiple Crypto Companies via Brevo email provider

Multiple crypto companies warn customers of phishing emails after alleged provider breach

Trezor, BitBox, CoinTracking, and their cryptocurrency users.

Attackers compromised accounts at the email provider Brevo and used legitimate crypto-company mailing infrastructure to send convincing phishing emails to customers, attempting to steal wallet backups and other sensitive information; Brevo later said 138 accounts had been breached and contacts from 43 accounts had been exported.

Source: The Record Media

September 13, 2026

Users of Tencent’s Sogou Input Method for Windows

Hackers exploit Tencent app flaw to deploy GrayRabbit malware

UNC3569, a China-aligned threat group

Attackers exploited a critical Sogou Input Method vulnerability to remotely execute code and install the GrayRabbit backdoor, which allowed them to execute commands, access files, collect system information and establish reverse shells on compromised Windows systems.

Source: Bleeping Computer


September 16, 2026

CenterPoint Energy and a portion of its customers

CenterPoint Energy confirms cyber attack after threat actor claims data theft

4d722e4d656f77

The threat actor claimed to have stolen roughly 7.49 million CenterPoint Energy customer records through an external-facing API, while the company confirmed that an unauthorized third party had obtained personal information belonging to some customers. The exposed information reportedly included names, Social Security numbers, phone numbers, service and billing addresses, account numbers and billing amounts. CenterPoint said its electricity and gas services remained operational and undisrupted while its investigation continued.

Source:teiss.co.uk

September 16, 2026

Texas-bound foreign-flagged oil tanker

US Coast Guard boarded a Texas-bound oil tanker to investigate a cyber attack, Bloomberg News reports

Unknown

The vessel’s onboard network was suspected to have been compromised by overseas cyber actors, prompting U.S. Coast Guard and FBI personnel to board the tanker on August 21, 2026, and examine its operational technology and IT systems. Authorities investigated the potential security impact, but no operational disruption, vessel instability, danger to the crew, or environmental impact was reported.

Source: Reuters

September 16, 2026

Dissidents, activists, and journalists worldwide.

Iranian hackers use CHOSEN BRICK Windows malware to spy on targets

Iranian state-linked hackers.

Iranian state-linked hackers used the CHOSEN BRICK Windows malware to compromise targeted devices and conduct surveillance against dissidents, activists, and journalists, allowing them to maintain access and monitor victims.

Source: Bleeping Computer


September 18, 2026

Job seekers and IT professionals, particularly web designers, engineers and cryptocurrency specialists, across more than 100 countries.

North Korean hackers infect thousands of devices across 100 countries as part of ‘WaterPlum’ campaign

WaterPlum — a North Korean-linked cyber actor group.

WaterPlum hackers infected at least 30,000 devices between December 2025 and July 2026 and stole cryptocurrency or wallet credentials from around 7,000 cryptocurrency wallets. The attackers posed as recruiters or technology companies, used fake job interviews to trick victims into downloading malicious files, and installed malware and remote-management tools to maintain access to infected devices. The campaign also enabled the attackers to potentially use compromised devices to gain access to companies where victims were later employed.

Source: The Record Media

September 19, 2026

Clop (Cl0p) ransomware leak site

ShinyHunters hacks Clop leak site, threatens to extort ransomware gang

ShinyHunters

ShinyHunters exploited an alleged unauthenticated file-upload flaw in Clop’s leak-site infrastructure, defaced the site and claimed to have stolen server data and private keys used for its onion service. The group then demanded an eight-figure payment from Clop and threatened to publish the allegedly stolen information, while Clop later responded through the hijacked site.

Source: Bleeping Computer

September 21, 2026

Ludwig Maximilian University of Munich (LMU Munich), Germany

Cyber attack hits University of Munich, potentially exposing student financial data

Unknown

An unauthorized attacker accessed an LMU IT system containing student enrollment data, and the university believed the information had been retrieved. The potentially exposed data included names, dates of birth, contact details, LMU email addresses, bank account information, health insurance numbers, student financial-aid identifiers and education records. LMU isolated the affected server and temporarily took some other systems offline as a precaution, which made some internal services unavailable and briefly interrupted student registration, although teaching and studies were not disrupted.

Source: The Record Media

September 21, 2026

Royal Belgian Table Tennis Federation (FRBTT) and its French-speaking branch, Association Francophone de Tennis de Table (AFTT)

Belgian table tennis, gymnastics federations hit by cyber attacks

Venus1337

Venus1337 claimed to have breached the Belgian table tennis federations and stolen nearly 1.7 GB of data linked to more than 66,800 members and 17,400 users, along with club administrative accounts. The attacker posted samples online, but the federation had not independently verified the claimed volume or categories of stolen data. The AFTT said its checks had not found evidence that its infrastructure or members’ phone numbers and email addresses had been compromised, and it strengthened security measures while the investigation continued.

Source: The Record Media

September 22, 2026

Windows users and organizations whose systems were infected with the malware.

New ClosedQuorum Windows malware uses AI for attack decisions

Unknown

ClosedQuorum malware autonomously used multiple AI models to decide its next actions on infected Windows systems, including stealing browser credentials, LSASS credentials and cryptocurrency-wallet data, injecting code and establishing persistence. The stolen information was sent to the operators through a Discord webhook, allowing the attack chain to operate with little or no human intervention.

Source: Bleeping Computer

September 24, 2026

Australian government

OpenAI agent hacked an Australian government website, CNBC says

OpenAI AI agent

The incident exposed non-public aggregated Medicare health statistics and internal files through unauthorized access, while authorities said there was no evidence that individual Medicare or patient records were accessed.

Open AI Hacked Aussie Govt Website

September 25, 2026

Dyfed-Powys police

Cyber attack on Dyfed-Powys police ‘may have accessed staff information

Unknown

The cyber attack disrupted some non-emergency police systems and may have exposed staff information, while there is currently no evidence that members of the public had their personal data compromised.

Source: theguardian.com

 
 
 


Back to Top 

New Ransomware/Malware Discovered in September 2026

New Ransomware

Summary

NodeRabbit

Previously undocumented Node.js/JavaScript RAT attributed to Iranian-linked Nimbus Manticore activity; delivered through fake coding-test archives.

BraZetsu

Python-based framework designed to turn compromised Windows machines into commercially valuable access for initial-access brokers.

RatHat

New Android malware using AI-assisted device navigation and abusing Accessibility and ADB capabilities to maintain deep control over infected devices.

Settra

Newly reported ransomware variant observed in retail and manufacturing attacks, using RMM tools, recovery disruption and BYOVD techniques.

RemControl

New Android malware-as-a-service platform targeting users through fake IPTV applications and malvertising, with banking and device-control capabilities.

Source for the above table: Bleeping Computer, Recorded Future News

 Back to Top  

 

Vulnerabilities/Patches Discovered in September 2026

Date

New Flaws/Fixes

Summary

September 1, 2026

CVE-2026-81578 and CVE-2026-82078

Attackers exploited recently patched PaperCut vulnerabilities to bypass authentication and steal database data from vulnerable servers in ongoing attacks.

September 2, 2026

CVE-2026-82329

Hackers had exploited a critical JFrog Artifactory authentication-bypass flaw to forge administrator tokens and gain administrative access, potentially allowing them to read or tamper with trusted software packages used by downstream systems.

September 4, 2026

CVE-2026-11645

Google had patched another Chrome zero-day that attackers were actively exploiting in the wild, with the flaw affecting Chrome’s V8 JavaScript engine and potentially allowing malicious code to execute through specially crafted web content.

September 7, 2026

CVE-2026-67276 and CVE-2026-86060

Attackers exploited two MikroTik RouterOS vulnerabilities to bypass SSH authentication and hijack vulnerable routers, giving them full administrative control.

September 13, 2026

CVE-2026-76461

Attackers actively exploited a critical Cisco Secure Email Gateway zero-day to send malicious emails that enabled unauthenticated remote command execution with root privileges on affected appliances.

September 22, 2026

CVE-2026-7273.

Attackers actively exploited a high-severity Zyxel GS1900 switch flaw to execute OS commands and steal sensitive data, with GreyNoise finding 996 compromised switches across 48 countries.

September 23, 2026

CVE-2026-87902

Hackers are actively exploiting a critical WordPress flaw to write malicious PHP files and execute shell commands on vulnerable websites, with attack activity reportedly surging after the vulnerability was disclosed.

September 24, 2026

CVE-2026-63077

Ransomware gangs are now exploiting a critical JetBrains TeamCity vulnerability to bypass authentication and execute arbitrary operating-system commands, potentially exposing credentials, configurations and CI/CD pipelines.

September 26, 2026 

CVE-2026-35273 

ShinyHunters has resumed attacks against vulnerable Oracle PeopleSoft servers by using a URL-encoding technique to bypass Web Application Firewall protections, allowing exploitation of the critical flaw and deployment of web shells across organizations in sectors including education, healthcare, government, technology and transportation. 

September 27, 2026 

CVE-2026-88771 and CVE-2026-88772  

Citrix confirmed that two critical NetScaler ADC and Gateway zero-day vulnerabilities were actively exploited in the wild, prompting urgent warnings for administrators to secure or temporarily take internet-exposed appliances offline and apply the released security updates.  

September 29, 2026 

CVE-2026-86950 

Apple has patched a CoreGraphics zero-day actively exploited in highly targeted attacks, where specially crafted files could trigger arbitrary code execution on vulnerable iPhone, iPad and Mac devices.  

September 29, 2026 

CVE-2026-88772 

Hackers exploited a Citrix NetScaler zero-day to gain root access, deploy web shells and tunneling malware, steal credentials, and potentially move deeper into internal networks, with attacks reported against organizations across government, finance, education, legal and professional services sectors. 

September 30, 2026 

CVE-2026-92370, CVE-2026-19743, CVE-2026-92368, CVE-2026-92369, CVE-2026-92371 

TeamViewer has urged users to update immediately after fixing five high-severity vulnerabilities that could allow attackers to bypass remote-session access controls, execute code, write files with elevated privileges, or escalate system privileges on vulnerable Windows, Linux and macOS systems.  

September 30, 2026 

CVE-2026-67279 

CISA has warned about a critical pre-authentication vulnerability in MikroTik RouterOS that could allow unauthenticated remote attackers to execute arbitrary code or disrupt vulnerable routers, urging organizations to secure exposed devices and apply available security updates.  

 Source for the above table: Bleeping Computer, Recorded Future  

 Back to Top

Warnings/Advisories/Reports/Analysis

News Type

Summary

Warning

SonicWall had warned administrators that attackers were actively exploiting two zero-day vulnerabilities in SMA 1000 appliances, urging them to apply the available fixes and check their systems for signs of compromise.

Warning

SAP warned that the maximum-severity OVERPASS vulnerability in the SAP Kernel could allow unprivileged attackers to execute arbitrary commands with administrative privileges and fully compromise affected SAP systems and business data.

Warning

ConnectWise had warned that a new ScreenConnect vulnerability affecting file-transfer functionality impacted both cloud and on-premises deployments, while no patch was yet available and temporary mitigations had been provided.

Report

Cybercriminals had created more than 360 fake government and news websites across Central Asia to lure users with bogus financial offers, steal personal information, and in some cases trick victims into installing malware that gave attackers access to their devices.

Warning

China’s top intelligence official had warned that advanced U.S. AI models could significantly lower the barriers to vulnerability discovery and malware development, potentially increasing cyber risks to China’s critical infrastructure.

Warning

Acronis warned that attackers had actively exploited a high-severity local privilege-escalation flaw in its cPanel/WHM and Plesk backup plugins in limited, targeted attacks, allowing low-privileged users to gain elevated access on vulnerable Linux servers.

Warning

Cisco warned that attackers had actively exploited a maximum-severity Cisco Identity Services Engine (ISE) zero-day to bypass authentication and gain unauthorized access to affected devices through a vulnerable API.

Warning

D-Link warned that a critical zero-day in DIR-822A routers could be remotely exploited without authentication to crash the DHCP service or execute commands, while a public proof-of-concept was already available and no patch had been released.

Warning

Check Point patched a critical Security Management Server zero-day that attackers had actively exploited to upload and execute arbitrary scripts on vulnerable systems, with a handful of customers already affected.

Report

The U.S. Department of Veterans Affairs criticized Baylor Genetics for delaying and inadequately sharing information about a June cybersecurity breach that exposed sensitive data of 30,263 veterans, including medical and insurance information and partial Social Security numbers.

Warning

Attackers are increasingly exploiting critical vulnerabilities in network-management platforms to gain remote control of enterprise infrastructure, with some attacks leading to credential theft, system compromise and ransomware deployment.

Report

U.S. lawmakers have introduced a bipartisan bill proposing voluntary cybersecurity standards and an optional certification program for telecom companies, following the major Salt Typhoon attacks that exposed weaknesses across the sector.

Report

Kiteworks urged customers to temporarily shut down its platform after receiving credible intelligence about a possible cyber attack, although the company said it had found no evidence of a confirmed compromise.

Report

Attackers exploited zero-day vulnerabilities in third-party security products to breach Bitget’s internal systems, steal high-privilege credentials and execute fraudulent withdrawal commands, resulting in the theft of approximately $388 million from hot and warm wallets, while cold wallets and customer account balances remained unaffected. 

  Sources: Bleeping Computer and Infosecurity Magazine

Back to Top