September’s cyber incidents did not follow a neat pattern. CenterPoint Energy faced a cybersecurity incident affecting corporate systems. Incidents and reported compromises involving the Royal Belgian Table Tennis Federation (FRBTT), FBI systems, Dyfed-Powys Police, an Australian government website and Aesto Health showed how attackers continue to find opportunities across vastly different sectors. From critical infrastructure and law enforcement to healthcare and public-facing services, the month’s incidents demonstrate just how widely cyber risk can spread.
Data exposure was another defining theme. Condé Nast, Mathspace, Vietnam’s APIS database, Gyazo and IDScan.net all featured in September’s cyber headlines, with some incidents involving potentially significant volumes of personal or user information. Particularly notable was the reported exposure associated with Vietnam’s APIS database, involving data linked to as many as 220 million records. As always, some figures and attacker claims remain subject to investigation and should be treated as provisional until independently confirmed.
Taken together, September’s incidents reinforce the importance of preparing for more than one type of cyber crisis.
Cyber Management Alliance helps your organisation build that readiness through Cyber Incident Response Plans and Playbooks creation and review services, Cyber Tabletop Exercises, Executive Cybersecurity Training, Third-Party Risk Assessments and cyber resilience assessments. The objective is not to promise that every attack can be prevented, but to reduce exposure, identify weaknesses earlier and ensure that when an incident does occur, teams know exactly how to respond, contain the damage and recover.
|
Date |
Victim |
Summary |
Threat Actor |
Business Impact |
Source Link |
|
September 1, 2026 |
Nutex Health |
Ransomware gang claims Nutex Health data breach |
Unknown ransomware gang |
A ransomware group claimed it had breached Nutex Health and stolen sensitive company and patient data, but the company had not publicly confirmed the attackers’ claims or the full scope of the alleged breach. |
|
|
September 5, 2026 |
Berlin state government, specifically two government departments. |
Berlin launches crisis response after hackers publish stolen data |
Unknown ransomware group |
Berlin’s state government launched a high-level crisis response after a ransomware group published stolen data from two government departments, while investigators assessed the extent of the compromise and the impact of the exposed information |
|
|
September 15, 2026 |
Organizations using vulnerable VMware vCenter Server systems. |
CISA: Critical VMware RCE flaw now exploited by ransomware gangs |
Unknown |
Ransomware gangs exploited the critical VMware vCenter vulnerability to gain remote code execution on vulnerable systems. The flaw had already been abused by attackers to deploy a reverse SSH tool for persistence and remote access, and CISA later confirmed that ransomware actors had joined the exploitation activity, putting organizations’ networks and sensitive data at risk. |
Source: Bleeping Computer |
|
September 28, 2026 |
Keio |
Japan's Keio confirms ransomware attack disrupted business systems |
Unknown |
The ransomware attack disrupted Keio’s business systems, including hospitality and payment-related services, while the company shut down its network to contain the incident; railway operations were not affected, and an investigation is underway to determine whether customer or business-partner data was accessed. |
Source: Bleeping Computer |
|
Date |
Victim |
Summary |
Threat Actor |
Business Impact |
Source Link |
|
September 1, 2026 |
Aesto Health and patients of its healthcare-provider clients |
Aesto Health says data breach affects over 9.5 million patients |
Unknown |
Aesto Health suffered a data breach after an unauthorized actor accessed a portion of its AWS infrastructure between December 2 and December 18, 2025, potentially exposing personal and protected health information belonging to 9,540,683 individuals, including names, dates of birth, medical information, health insurance details, government IDs, financial account information and Social Security numbers. |
Source: Bleeping Computer |
|
September 1, 2026 |
Novocure |
Novocure data breach affects more than 1,400 cancer patients |
ShinyHunters |
Novocure suffered unauthorized access to some of its information systems in mid-August 2026, exposing internal patient ID numbers from more than 1,400 U.S. patient records, identifying information for fewer than 50 other patients, healthcare-provider contact details, and employee contact information; the company said its medical treatment devices and operations were not affected. |
Source: Bleeping Computer |
|
September 2, 2026 |
Dropbox users |
Dropbox accounts breached through Lenovo email verification flaw |
Unknown |
Attackers exploited a flaw in Lenovo’s email verification process to create fraudulent Lenovo IDs and use them to access matching Dropbox accounts without passwords; around 5,000 accounts were accessed, with some users’ files viewed and downloaded. |
Source: Bleeping Computer |
|
September 5, 2026 |
Trezor customers |
Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted |
Unknown |
The ShipMonk breach exposed personal and order information belonging to approximately 67,000 additional U.S. Trezor customers whose older records should have been deleted. The exposed information included names, email addresses, phone numbers, shipping addresses and order numbers, increasing the risk of phishing, scams and potential physical-security concerns. |
|
|
September 5, 2026 |
JetBrains Cadence |
Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials |
Unknown |
Attackers exploited an unpatched critical TeamCity vulnerability to breach JetBrains’ Cadence environment, gaining access to the Cadence server and potentially compromising AWS credentials, secrets, backups, and other credentials available to its executions. JetBrains urged Cadence users to revoke and rotate potentially exposed credentials. |
|
|
September 6, 2026 |
Bimbo Bakeries USA |
Bimbo Bakeries USA Confirms Data Breach in Oracle EBS Zero-Day Attack |
Clop |
Bimbo Bakeries USA had its employee data stolen after attackers exploited an Oracle E-Business Suite zero-day through a third-party vendor, with one stolen file containing victims’ names and Social Security numbers; the company had not disclosed the total number of affected individuals. |
|
|
September 7, 2026 |
Condé Nast |
Condé Nast Data of 32.8 Million Users Offered for Sale After WIRED Leak |
Unknown |
A database containing data from about 32.8 million Condé Nast user accounts was offered for $15,000 on a Russian-language cybercrime forum; a sample was found to match genuine Condé Nast account data collected in 2025, although Condé Nast had not publicly confirmed the breach. The exposed information reportedly included email addresses, names, postal addresses, dates of birth and phone numbers, but no passwords or payment-card data. |
|
|
September 7, 2026 |
Microsoft 365 users and organizations, particularly executives and staff across construction, healthcare, finance, real estate, and professional services. |
Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks |
PREY-0058, with links to UNC6671 and activity associated with Cinder/Pink-affiliated groups. |
Attackers impersonated IT help-desk staff in phone calls, tricked executives into handing over Microsoft 365 credentials and MFA approvals, stole session tokens, accessed SharePoint, OneDrive, Exchange and Box data, and then exfiltrated information for extortion |
Source: thehackernews.com |
|
September 7, 2026 |
Mathspace |
Mathspace discloses data breach affecting over 1 million people |
Unknown |
Mathspace disclosed that attackers had breached its systems and stolen personal information belonging to more than 1 million students, staff, and parents. |
Source: Bleeping Computer |
|
September 8, 2026 |
APIS database of 220M passenger and crew records belonging to Vietnam |
Massive data breach sees 220 million traveler records exposed - nine years of airline info leaked including passenger and passport details |
Unknown |
A misconfigured cloud database exposed around 220 million passenger and crew records, including names, passport and travel-document numbers, nationalities, birth dates, flight details, seat assignments and other travel information; the database was secured after researchers notified Vietnamese authorities and affected airlines. |
Source: techradar.com |
|
September 8, 2026 |
Florida Department of Highway Safety and Motor Vehicles (FLHSMV), specifically its DAVID driver-information database |
ShinyHunters hackers claim breach of Florida "DAVID" DMV database |
ShinyHunters |
ShinyHunters claimed it had breached Florida’s DAVID DMV database and stolen more than 200,000 driver records, which it allegedly obtained from the state’s online driver-information platform. The claim involved stolen personal information, but the breach had not been independently confirmed by Florida authorities. |
Source: Bleeping Computer |
|
September 9, 2026 |
Veradigm Inc. and a limited group of its healthcare customers |
Veradigm confirms patient data exposed in third-party data breach |
Unknown |
An unauthorized party used stolen credentials from a third-party vendor to access a Veradigm API and download patient information, including Social Security numbers in some cases; however, clinical data was not compromised and Veradigm’s systems and services were not disrupted. |
Source: cybersecuritynews.com |
|
September 10, 2026 |
IDScan and more than 150 million individuals whose driver’s license records were stored by the company |
ID verification giant IDScan confirms data breach with more than 150 million driver’s licenses stolen |
Unknown |
Hackers stole driver’s license records from IDScan’s cloud systems, exposing names, driver’s license numbers, passport and other government-issued identity numbers, with a dark-web database reportedly providing access to more than 150 million records and photos. |
Source: techcrunch.com |
|
September 10, 2026 |
AdaptHealth |
4.1 Million Impacted by AdaptHealth Data Breach |
Unknown |
AdaptHealth disclosed that an attacker had accessed its systems and stolen personal, health, and insurance information belonging to more than 4.1 million people. |
Source: securityweek.com |
|
September 10, 2026 |
Greenberg Traurig |
Law firm Greenberg Traurig says 'limited' data posted to dark web as cyber attacks mount |
Unknown |
Greenberg Traurig said an unauthorized actor had accessed and posted a limited number of the firm’s documents on the dark web, affecting a small number of clients; the firm said its own systems had not been compromised, although some exposed information included Social Security details. |
Source: Reuters |
|
September 10, 2026 |
Weverse, the South Korean fan community platform operated by HYBE |
Data breach hits Weverse, exposing confidential data of over 420,000 accounts |
Unknown |
Weverse confirmed that confidential information linked to 422,584 accounts had been compromised, including internal user IDs and purchase, payment-method, transaction, cancellation and refund details; the company said the exposed internal identifiers could not directly identify users or be used on their own for payment fraud. |
Source: teiss.co.uk |
|
September 12, 2026 |
Revolut |
Revolut confirms customer data breach through fake government requests |
Unknown |
Revolut disclosed that an unauthorized party used fraudulent requests sent from a legitimate government agency email domain to obtain sensitive customer information, including birth dates, contact details, passport and driver’s license copies, and potentially verification selfies, account statements and transaction histories; Revolut said its systems and customer funds remained unaffected. |
Source: techcrunch.com |
|
September 12, 2026 |
Florida Department of Highway Safety and Motor Vehicles (FLHSMV), specifically its DAVID driver and vehicle database |
Florida says motor vehicle data breach tied to credentials stolen from officer’s personal |
ShinyHunters |
ShinyHunters claimed access to Florida’s motor vehicle database, and FLHSMV later confirmed that a breach had occurred after attackers used credentials belonging to a Plant City police officer that had been improperly stored on the officer’s personal device; the agency said the breach was quickly contained and was no longer ongoing. |
Source: The Record Media |
|
September 14, 2026 |
Digital Agency, Government of Japan |
Japan's Digital Agency says VPN flaw exposed 246,000 personnel records |
Unknown |
An attacker exploited a vulnerability in a VPN device used by Japan’s Government Solution Service to gain unauthorized access to an internal system as the incident potentially exposed around 246,000 records, including names, email addresses, telephone numbers and physical addresses. |
Source: Bleeping Computer |
|
September 16, 2026 |
Spain’s Data Protection Agency (AEPD) |
Spain's data agency gets first report of AI-powered data breach |
AI-powered autonomous agent; the specific operator or threat actor was not identified. |
The AI agent reportedly identified vulnerabilities, gained access to the organization’s systems, searched applications for additional weaknesses, modified personal data and accessed financial documents, although the AEPD had not yet independently verified the incident. |
Source: Bleeping Computer |
|
September 17, 2026 |
Russia’s Central Election Commission and contractors involved in the Vybory election administration platform, including Rostelecom |
Hackers claim breach of Russian election systems days before parliamentary vote |
CikLeak |
CikLeak claimed it had breached systems linked to Russia’s Central Election Commission and election-system contractors and had stolen internal documents, server configurations, passwords and employee communications; the stolen material was reportedly authenticated, although it remained unclear whether systems directly involved in voting or ballot counting had been accessed. |
Source: The Record Media |
|
September 18, 2026 |
Gyazo |
Gyazo server flaw exploited to steal 23.6 million user records |
Unknown |
Attackers exploited a vulnerability in Gyazo’s image-upload server to gain unauthorized access and execute commands, stealing approximately 23.62 million user records and metadata from about 490 million images. The exposed information included names, email addresses, password hashes, user and device IDs, login-session IDs, profile details and other account data, while image metadata included IP addresses, EXIF location data, OCR text and hashed passphrases. Gyazo temporarily restricted access to some images because it could not rule out that private images had been viewed. |
Source: Bleeping Computer |
|
September 22, 2026 |
Federal Bureau of Investigation (FBI) |
Hacking group ShinyHunters claims it breached the FBI, stole agents’ and applicants’ data |
ShinyHunters |
ShinyHunters claimed it breached FBI systems and stole sensitive information belonging to thousands of FBI agents and job applicants, including names, home addresses and phone numbers. The group reportedly accessed an Oracle PeopleSoft server before pivoting into an Amazon-hosted government cloud environment and claimed to have taken terabytes of data. The FBI jobs website and special-agent applicant portal were also reportedly disrupted and taken offline for maintenance. The FBI had not independently confirmed the full scope of the alleged data theft at the time of the report. |
Source: techcrunch.com |
|
September 22, 2026 |
BigCommerce merchants and their customers |
BigCommerce merchants impacted by third-party app data breach |
Unknown |
Attackers compromised credentials belonging to the third-party Ribon and Ribon 1.5 applications and used them between September 13 and September 17, 2026, to access shopper data from affected BigCommerce stores and inject malicious scripts into a small number of merchant storefronts. Exposed information included customers’ names, email addresses, phone numbers and shipping addresses. BigCommerce said its own platform and systems were not breached, and passwords and payment-card information were not exposed. |
|
|
September 24, 2026 |
Astrana |
Astrana latest healthcare tech firm to report data breach to SEC |
Unknown |
The cyberattack gave hackers unauthorized access to Astrana’s servers, potentially exposing confidential and sensitive information and forcing the company to restore some systems from clean backups. |
Source: The Record Media |
|
September 29, 2026 |
East Suffolk and North Essex NHS Foundation Trust (ESNEFT) |
10 NHS staff suspended over data breach involving Noah Woods |
Unknown |
The data breach led to 10 NHS staff members being suspended amid an investigation into alleged unauthorised access to the medical records of Noah Woods, raising concerns over patient confidentiality and the handling of sensitive health information. |
Source: The BBC |
|
September 30, 2026 |
Bee Cheng Hiang |
Singapore reports first data breach linked to AI use |
Unknown |
An AI-assisted coding error at Bee Cheng Hiang exposed the email addresses of 95,364 customers through bulk marketing emails, marking Singapore’s first reported AI-related data breach, although no further misuse of the exposed information has been found. |
Source: Bloomberg.com |
|
September 30, 2026 |
Times Car Rental |
Times Car Rental says data breach affected 6.6 million accounts |
Unknown |
The data breach affected approximately 6.6 million Times Car Rental accounts, with about 1.6 million documents accessed, including images used to verify customers’ personal information. |
|
|
September 30, 2026 |
U.S. Department of Defense / Defense Manpower Data Center (DMDC) |
Pentagon breach exposed sensitive data on nearly 3 million people |
Unknown |
A Pentagon Defense Manpower Data Center breach exposed sensitive personal information of 2.76 million living people and 294,000 deceased individuals, including Social Security numbers and military or civilian job details, although officials said there is currently no evidence the data has been misused. |
Source: abcnews.com |
|
Date |
Victim |
Summary |
Threat Actor |
Business Impact |
Source Link |
|
September 2, 2026 |
Approximately 80,000 freelancers who used an unnamed freelance employment technology company |
US charges Russian for infecting 80,000 freelancers with malware |
Searzhudin Tamirlanovich Aktulaev |
Aktulaev allegedly used 255 fake accounts to send malicious Excel attachments to around 80,000 freelancers between June 2016 and November 2017, infecting their devices with TVRAT and DarkVNC malware that enabled remote access and the theft of e-commerce credentials and personally identifiable information. |
Source: Bleeping Computer |
|
September 8, 2026 |
Springfield Public Schools and Everett City Hall, Massachusetts |
Massachusetts school district, city hall shutter after cyber incidents. |
Unknown |
Cyber incidents disrupted essential systems at Springfield Public Schools, affecting phone lines and other services and forcing schools to close temporarily, while a separate attack disrupted Everett City Hall’s internal network and systems, leading the city to close the building to the public as officials investigated and worked to restore operations. |
Source: The Record Media |
|
September 8, 2026 |
Stadtwerke Landsberg, a municipal utility in Bavaria, Germany |
Cyber attack encrypts systems at Bavarian municipal utility |
Unknown |
Hackers encrypted the utility’s central IT network, disrupting office systems and limiting staff communications, while electricity, water and other essential services continued operating; the utility also warned that customer personal and banking data might have been accessed or stolen. |
Source: The Record Media |
|
September 10, 2026 |
Multiple Crypto Companies via Brevo email provider |
Multiple crypto companies warn customers of phishing emails after alleged provider breach |
Trezor, BitBox, CoinTracking, and their cryptocurrency users. |
Attackers compromised accounts at the email provider Brevo and used legitimate crypto-company mailing infrastructure to send convincing phishing emails to customers, attempting to steal wallet backups and other sensitive information; Brevo later said 138 accounts had been breached and contacts from 43 accounts had been exported. |
Source: The Record Media |
|
September 13, 2026 |
Users of Tencent’s Sogou Input Method for Windows |
Hackers exploit Tencent app flaw to deploy GrayRabbit malware |
UNC3569, a China-aligned threat group |
Attackers exploited a critical Sogou Input Method vulnerability to remotely execute code and install the GrayRabbit backdoor, which allowed them to execute commands, access files, collect system information and establish reverse shells on compromised Windows systems. |
Source: Bleeping Computer
|
|
September 16, 2026 |
CenterPoint Energy and a portion of its customers |
CenterPoint Energy confirms cyber attack after threat actor claims data theft |
4d722e4d656f77 |
The threat actor claimed to have stolen roughly 7.49 million CenterPoint Energy customer records through an external-facing API, while the company confirmed that an unauthorized third party had obtained personal information belonging to some customers. The exposed information reportedly included names, Social Security numbers, phone numbers, service and billing addresses, account numbers and billing amounts. CenterPoint said its electricity and gas services remained operational and undisrupted while its investigation continued. |
Source:teiss.co.uk |
|
September 16, 2026 |
Texas-bound foreign-flagged oil tanker |
US Coast Guard boarded a Texas-bound oil tanker to investigate a cyber attack, Bloomberg News reports |
Unknown |
The vessel’s onboard network was suspected to have been compromised by overseas cyber actors, prompting U.S. Coast Guard and FBI personnel to board the tanker on August 21, 2026, and examine its operational technology and IT systems. Authorities investigated the potential security impact, but no operational disruption, vessel instability, danger to the crew, or environmental impact was reported. |
Source: Reuters
|
|
September 16, 2026 |
Dissidents, activists, and journalists worldwide. |
Iranian hackers use CHOSEN BRICK Windows malware to spy on targets |
Iranian state-linked hackers. |
Iranian state-linked hackers used the CHOSEN BRICK Windows malware to compromise targeted devices and conduct surveillance against dissidents, activists, and journalists, allowing them to maintain access and monitor victims. |
Source: Bleeping Computer
|
|
September 18, 2026 |
Job seekers and IT professionals, particularly web designers, engineers and cryptocurrency specialists, across more than 100 countries. |
North Korean hackers infect thousands of devices across 100 countries as part of ‘WaterPlum’ campaign |
WaterPlum — a North Korean-linked cyber actor group. |
WaterPlum hackers infected at least 30,000 devices between December 2025 and July 2026 and stole cryptocurrency or wallet credentials from around 7,000 cryptocurrency wallets. The attackers posed as recruiters or technology companies, used fake job interviews to trick victims into downloading malicious files, and installed malware and remote-management tools to maintain access to infected devices. The campaign also enabled the attackers to potentially use compromised devices to gain access to companies where victims were later employed. |
Source: The Record Media |
|
September 19, 2026 |
Clop (Cl0p) ransomware leak site |
ShinyHunters hacks Clop leak site, threatens to extort ransomware gang |
ShinyHunters |
ShinyHunters exploited an alleged unauthenticated file-upload flaw in Clop’s leak-site infrastructure, defaced the site and claimed to have stolen server data and private keys used for its onion service. The group then demanded an eight-figure payment from Clop and threatened to publish the allegedly stolen information, while Clop later responded through the hijacked site. |
Source: Bleeping Computer |
|
September 21, 2026 |
Ludwig Maximilian University of Munich (LMU Munich), Germany |
Cyber attack hits University of Munich, potentially exposing student financial data |
Unknown |
An unauthorized attacker accessed an LMU IT system containing student enrollment data, and the university believed the information had been retrieved. The potentially exposed data included names, dates of birth, contact details, LMU email addresses, bank account information, health insurance numbers, student financial-aid identifiers and education records. LMU isolated the affected server and temporarily took some other systems offline as a precaution, which made some internal services unavailable and briefly interrupted student registration, although teaching and studies were not disrupted. |
Source: The Record Media |
|
September 21, 2026 |
Royal Belgian Table Tennis Federation (FRBTT) and its French-speaking branch, Association Francophone de Tennis de Table (AFTT) |
Belgian table tennis, gymnastics federations hit by cyber attacks |
Venus1337 |
Venus1337 claimed to have breached the Belgian table tennis federations and stolen nearly 1.7 GB of data linked to more than 66,800 members and 17,400 users, along with club administrative accounts. The attacker posted samples online, but the federation had not independently verified the claimed volume or categories of stolen data. The AFTT said its checks had not found evidence that its infrastructure or members’ phone numbers and email addresses had been compromised, and it strengthened security measures while the investigation continued. |
Source: The Record Media |
|
September 22, 2026 |
Windows users and organizations whose systems were infected with the malware. |
New ClosedQuorum Windows malware uses AI for attack decisions |
Unknown |
ClosedQuorum malware autonomously used multiple AI models to decide its next actions on infected Windows systems, including stealing browser credentials, LSASS credentials and cryptocurrency-wallet data, injecting code and establishing persistence. The stolen information was sent to the operators through a Discord webhook, allowing the attack chain to operate with little or no human intervention. |
Source: Bleeping Computer |
|
September 24, 2026 |
Australian government |
OpenAI agent hacked an Australian government website, CNBC says |
OpenAI AI agent |
The incident exposed non-public aggregated Medicare health statistics and internal files through unauthorized access, while authorities said there was no evidence that individual Medicare or patient records were accessed. |
|
|
September 25, 2026 |
Dyfed-Powys police |
Cyber attack on Dyfed-Powys police ‘may have accessed staff information |
Unknown |
The cyber attack disrupted some non-emergency police systems and may have exposed staff information, while there is currently no evidence that members of the public had their personal data compromised. |
Source: theguardian.com |
|
New Ransomware |
Summary |
|
NodeRabbit |
Previously undocumented Node.js/JavaScript RAT attributed to Iranian-linked Nimbus Manticore activity; delivered through fake coding-test archives. |
|
BraZetsu |
Python-based framework designed to turn compromised Windows machines into commercially valuable access for initial-access brokers. |
|
RatHat |
New Android malware using AI-assisted device navigation and abusing Accessibility and ADB capabilities to maintain deep control over infected devices. |
|
Settra |
Newly reported ransomware variant observed in retail and manufacturing attacks, using RMM tools, recovery disruption and BYOVD techniques. |
|
RemControl |
New Android malware-as-a-service platform targeting users through fake IPTV applications and malvertising, with banking and device-control capabilities. |
|
Date |
New Flaws/Fixes |
Summary |
|
September 1, 2026 |
CVE-2026-81578 and CVE-2026-82078 |
Attackers exploited recently patched PaperCut vulnerabilities to bypass authentication and steal database data from vulnerable servers in ongoing attacks. |
|
September 2, 2026 |
CVE-2026-82329 |
Hackers had exploited a critical JFrog Artifactory authentication-bypass flaw to forge administrator tokens and gain administrative access, potentially allowing them to read or tamper with trusted software packages used by downstream systems. |
|
September 4, 2026 |
CVE-2026-11645 |
Google had patched another Chrome zero-day that attackers were actively exploiting in the wild, with the flaw affecting Chrome’s V8 JavaScript engine and potentially allowing malicious code to execute through specially crafted web content. |
|
September 7, 2026 |
CVE-2026-67276 and CVE-2026-86060 |
Attackers exploited two MikroTik RouterOS vulnerabilities to bypass SSH authentication and hijack vulnerable routers, giving them full administrative control. |
|
September 13, 2026 |
CVE-2026-76461 |
Attackers actively exploited a critical Cisco Secure Email Gateway zero-day to send malicious emails that enabled unauthenticated remote command execution with root privileges on affected appliances. |
|
September 22, 2026 |
CVE-2026-7273. |
Attackers actively exploited a high-severity Zyxel GS1900 switch flaw to execute OS commands and steal sensitive data, with GreyNoise finding 996 compromised switches across 48 countries. |
|
September 23, 2026 |
CVE-2026-87902 |
Hackers are actively exploiting a critical WordPress flaw to write malicious PHP files and execute shell commands on vulnerable websites, with attack activity reportedly surging after the vulnerability was disclosed. |
|
September 24, 2026 |
CVE-2026-63077 |
Ransomware gangs are now exploiting a critical JetBrains TeamCity vulnerability to bypass authentication and execute arbitrary operating-system commands, potentially exposing credentials, configurations and CI/CD pipelines. |
|
September 26, 2026 |
CVE-2026-35273 |
ShinyHunters has resumed attacks against vulnerable Oracle PeopleSoft servers by using a URL-encoding technique to bypass Web Application Firewall protections, allowing exploitation of the critical flaw and deployment of web shells across organizations in sectors including education, healthcare, government, technology and transportation. |
|
September 27, 2026 |
CVE-2026-88771 and CVE-2026-88772 |
Citrix confirmed that two critical NetScaler ADC and Gateway zero-day vulnerabilities were actively exploited in the wild, prompting urgent warnings for administrators to secure or temporarily take internet-exposed appliances offline and apply the released security updates. |
|
September 29, 2026 |
CVE-2026-86950 |
Apple has patched a CoreGraphics zero-day actively exploited in highly targeted attacks, where specially crafted files could trigger arbitrary code execution on vulnerable iPhone, iPad and Mac devices. |
|
September 29, 2026 |
CVE-2026-88772 |
Hackers exploited a Citrix NetScaler zero-day to gain root access, deploy web shells and tunneling malware, steal credentials, and potentially move deeper into internal networks, with attacks reported against organizations across government, finance, education, legal and professional services sectors. |
|
September 30, 2026 |
CVE-2026-92370, CVE-2026-19743, CVE-2026-92368, CVE-2026-92369, CVE-2026-92371 |
TeamViewer has urged users to update immediately after fixing five high-severity vulnerabilities that could allow attackers to bypass remote-session access controls, execute code, write files with elevated privileges, or escalate system privileges on vulnerable Windows, Linux and macOS systems. |
|
September 30, 2026 |
CVE-2026-67279 |
CISA has warned about a critical pre-authentication vulnerability in MikroTik RouterOS that could allow unauthenticated remote attackers to execute arbitrary code or disrupt vulnerable routers, urging organizations to secure exposed devices and apply available security updates. |
|
News Type |
Summary |
|
Warning |
SonicWall had warned administrators that attackers were actively exploiting two zero-day vulnerabilities in SMA 1000 appliances, urging them to apply the available fixes and check their systems for signs of compromise. |
|
Warning |
SAP warned that the maximum-severity OVERPASS vulnerability in the SAP Kernel could allow unprivileged attackers to execute arbitrary commands with administrative privileges and fully compromise affected SAP systems and business data. |
|
Warning |
ConnectWise had warned that a new ScreenConnect vulnerability affecting file-transfer functionality impacted both cloud and on-premises deployments, while no patch was yet available and temporary mitigations had been provided. |
|
Report |
Cybercriminals had created more than 360 fake government and news websites across Central Asia to lure users with bogus financial offers, steal personal information, and in some cases trick victims into installing malware that gave attackers access to their devices. |
|
Warning |
China’s top intelligence official had warned that advanced U.S. AI models could significantly lower the barriers to vulnerability discovery and malware development, potentially increasing cyber risks to China’s critical infrastructure. |
|
Warning |
Acronis warned that attackers had actively exploited a high-severity local privilege-escalation flaw in its cPanel/WHM and Plesk backup plugins in limited, targeted attacks, allowing low-privileged users to gain elevated access on vulnerable Linux servers. |
|
Warning |
Cisco warned that attackers had actively exploited a maximum-severity Cisco Identity Services Engine (ISE) zero-day to bypass authentication and gain unauthorized access to affected devices through a vulnerable API. |
|
Warning |
D-Link warned that a critical zero-day in DIR-822A routers could be remotely exploited without authentication to crash the DHCP service or execute commands, while a public proof-of-concept was already available and no patch had been released. |
|
Warning |
Check Point patched a critical Security Management Server zero-day that attackers had actively exploited to upload and execute arbitrary scripts on vulnerable systems, with a handful of customers already affected. |
|
Report |
The U.S. Department of Veterans Affairs criticized Baylor Genetics for delaying and inadequately sharing information about a June cybersecurity breach that exposed sensitive data of 30,263 veterans, including medical and insurance information and partial Social Security numbers. |
|
Warning |
Attackers are increasingly exploiting critical vulnerabilities in network-management platforms to gain remote control of enterprise infrastructure, with some attacks leading to credential theft, system compromise and ransomware deployment. |
|
Report |
U.S. lawmakers have introduced a bipartisan bill proposing voluntary cybersecurity standards and an optional certification program for telecom companies, following the major Salt Typhoon attacks that exposed weaknesses across the sector. |
|
Report |
Kiteworks urged customers to temporarily shut down its platform after receiving credible intelligence about a possible cyber attack, although the company said it had found no evidence of a confirmed compromise. |
|
Report |
Attackers exploited zero-day vulnerabilities in third-party security products to breach Bitget’s internal systems, steal high-privilege credentials and execute fraudulent withdrawal commands, resulting in the theft of approximately $388 million from hot and warm wallets, while cold wallets and customer account balances remained unaffected. |