CISA added four actively exploited flaws to its KEV catalog in a single day, including a CVSS 10.0 GitLab path traversal bug probed within hours of disclosure, while Anthropic detailed Russian espionage, Chinese distillation and criminal misuse of Claude, and Florida confirmed its DMV database was breached with a stolen police account.
🔴 CRITICAL (3)
GitLab patches CVSS 10.0 path traversal flaw CVE-2026-85706, exploited within a day Confirmed
GitLab released fixes for CVE-2026-85706, a path traversal bug in the repository commits API that unauthenticated attackers can use to read arbitrary files from a GitLab server, rated 10.0. Security firms observed in-the-wild probes within hours of the September 10 disclosure, and CISA added the flaw to its Known Exploited Vulnerabilities catalog on September 11 with a September 14 deadline for federal agencies. Self-managed GitLab administrators should upgrade immediately and rotate any credentials or tokens the server may have exposed.
JFrog Artifactory flaws chained to gain admin control and plant Rust backdoor Confirmed
Attackers chained two JFrog Artifactory vulnerabilities to bypass authentication, take administrative control of self-hosted servers that build pipelines pull from, and install a Rust backdoor. Cloud security firm Wiz observed the activity between August 15 and September 8; JFrog had already fixed both flaws, so only servers left unpatched were exposed. CISA added CVE-2026-42016 and CVE-2026-42018 to its Known Exploited Vulnerabilities catalog on September 11 with a September 25 deadline for federal agencies.
Sources CISA|BleepingComputer|The Hacker News
CISA adds ConnectWise ScreenConnect CVE-2026-84869 to KEV after unauthorised file transfer reports Confirmed
ConnectWise patched an authentication failure in ScreenConnect, tracked as CVE-2026-84869 and rated 9.9, that allowed files to be transferred and executed inside an active remote support or access session without authorisation or user confirmation. The fix ships from ScreenConnect client version 26.6.5 onwards; server components are not affected. CISA added the flaw to the Known Exploited Vulnerabilities catalog on September 11 with a September 14 deadline for federal agencies, and ConnectWise advised administrators to remove the TransferFiles permission from any open sessions.
Sources CISA|ConnectWise|Computerworld
🟠 HIGH (5)
Anthropic report details Russian espionage, Chinese distillation and criminal misuse of Claude Confirmed
Anthropic’s September threat intelligence report covers misuse it identified and disrupted between December 2025 and August 2026. It describes a Russian state-linked group it calls GTG-20006, with tradecraft matching Midnight Blizzard, that used Claude to rebuild malware after detection and automate intrusion workflows, and seven China-based labs it says ran industrial-scale distillation against its models. The company also details criminal operations that used Claude to automate exploitation and to extract secrets from Android apps at scale, and says it banned the accounts and shared intelligence with authorities.
Sources Anthropic|The Hacker News|SecurityWeek|BleepingComputer
Florida confirms DAVID driver database breach via stolen police credentials Confirmed
The Florida Department of Highway Safety and Motor Vehicles confirmed that its DAVID driver database was accessed with credentials belonging to a police department employee, days after the ShinyHunters extortion gang claimed it took more than 200,000 driver records. The state has not published a record count, so the volume of exposed data remains unverified. Affected residents should watch for identity theft attempts and treat unsolicited licence or vehicle registration messages as suspect.
Sources BleepingComputer
Brevo account compromise behind phishing of 347,000 Trezor users Confirmed
Hardware wallet maker Trezor says attackers used access to its email marketing provider Brevo to send phishing messages to roughly 347,000 newsletter subscribers, with about 2,500 people clicking the embedded link before Trezor disabled the domain. Mailing lists belonging to BitBox and CoinTracking were abused through the same Brevo account. Trezor says no other Trezor system was affected; customers should treat any request for wallet recovery words or seed phrases as fraudulent, because legitimate vendors never ask for them.
Sources SecurityWeek|BleepingComputer
China-linked UNC3569 used Sogou Input Method flaw to deploy GRAYRABBIT backdoor Confirmed
Gen Digital reported that a China-linked group it tracks as UNC3569 exploited a flaw in Sogou Input Method, one of the most widely used Chinese-language keyboards on Windows, to install the GRAYRABBIT backdoor. The campaign began with a crafted link and ended with the attacker holding the same access as the logged-in user. Tencent, which owns Sogou, has been notified; administrators should update the input method and hunt for the published indicators of compromise.
Sources The Hacker News
PaperCut replaces emergency patches for two actively exploited flaws with maintenance releases Confirmed
PaperCut published regular maintenance releases for NG and MF versions 26.0.5, 25.0.13 and 24.1.10 that supersede the emergency patches issued for two vulnerabilities under active exploitation. The earlier campaign, attributed to a likely Russian-speaking actor, used hundreds of AI agents to develop and test exploits against exposed print servers, affecting about 395 organisations. Administrators still running emergency-patch workarounds should move to the maintenance release and confirm the workarounds are removed.
🟡 MEDIUM (5)
Conti ransomware developer sentenced to four years in US prison Confirmed
Oleksii Lytvynenko, a Ukrainian national arrested in Ireland in 2023, has been sentenced in the United States to four years in prison for his role as a developer for the Conti ransomware operation. Conti attacked organisations worldwide through 2021 and 2022 before the crew shut down and its members dispersed into other extortion groups. The case is one of a small number of prosecutions tied to Conti personnel.
Sources SecurityWeek|BleepingComputer
Threat actor generated one million personalised fraud emails in three days Confirmed
Researchers tracked a criminal operation that used AI to produce about one million individually tailored malicious emails in three days, removing the usual trade-off between campaign volume and apparent credibility. The messages read as personal correspondence rather than bulk mail, which complicates filtering. Defenders should pair mail inspection with identity and payment controls that catch a convincing message when it does reach an inbox.
Sources DarkReading
Cyberattacks on law firms nearly double as stolen documents appear on the dark web Confirmed
Greenberg Traurig confirmed that documents linked to the firm were posted on the dark web, while BakerHostetler recorded a near doubling of incidents involving law firms in 2025. Legal practices hold privileged and deal-related material that extortion crews value for follow-on pressure on clients and counterparties. Firms should treat client file exposure as both a security incident and a professional obligations matter.
Sources Decrypt
CISA: crafted image can crash Orthanc DICOM medical imaging servers Confirmed
CISA issued a medical advisory for Orthanc, an open source DICOM server used to store and route medical imaging, warning that an authenticated remote attacker can trigger a heap buffer overflow by supplying a crafted PNG or JPEG file, crashing the process and causing a denial of service. Healthcare operators exposing Orthanc to untrusted networks should apply the vendor update and restrict access to the interface.
Sources CISA
Public exploit released for unauthenticated RCE in ILIAS learning platform Confirmed
An exploit for CVE-2026-80428 was published on Exploit-DB, describing unauthenticated PHP object injection through the Shibboleth integration in ILIAS e-learning deployments before 9.22, 10.10 and 11.3 that can lead to remote code execution. A public proof of concept lowers the bar for opportunistic scanning of internet-facing learning platforms. Administrators should patch and review web server logs for the related request patterns.
Sources Exploit-DB
⚪ WATCH (5)
SANS ISC describes an AI agent harvesting and reselling stolen LLM access
A SANS ISC diary describes an attacker using a semi-autonomous coding agent to find poorly secured LLM resale gateways, obtain API access through ordinary web flaws and account farming, validate the stolen capacity, and aggregate it behind a single gateway of their own. The case shows how quickly stolen model access can be turned into a resale product. Teams running internal or resold model endpoints should review gateway authentication and watch for capacity anomalies.
Sources SANS ISC
InjectEave technique uses invisible Unicode to slip past phishing filters
SecurityWeek’s roundup covers InjectEave, a technique that hides payloads in invisible Unicode characters to bypass phishing filters, alongside a US$10 million bounty on an Iranian cyber official and reporting on the military ties of the Chinese hacking group QTFY. Each item is low profile on its own but relevant to mail filtering and threat intelligence teams tracking evasion tradecraft.
Sources SecurityWeek
Research: click rates are a poor measure of phishing awareness
An analysis of 2.47 million simulated phishing attacks argues that organisations should measure credential leaks and user reporting rather than click-through rates, which move with campaign design and workforce role. The authors say click metrics can push security leaders toward the wrong training investment and away from controls that stop a successful phish from becoming a breach.
Sources SecurityWeek
CISA and partners publish guidance on communications during IT and OT outages
CISA, the FBI and international partners released best practices for planning and delivering clear, timely communications to customers and regulators during IT and OT outages, whether caused by cyberattacks or failures. The guidance lands amid a broader regulatory push for faster and more transparent breach and outage notification.
Sources CISA|DarkReading
Blockstream refuses ransom for return of $47 million in Bitcoin from Liquid hack
Blockstream says it will not pay for the return of about 598.5 BTC still outstanding after the roughly $320 million exploit of the Liquid Network, calling the demand theft and stating it will involve law enforcement if the funds are not returned. Most of the withdrawn funds came back after the attackers asked for a bug fix rather than a bounty. Chainalysis has published an analysis of how the withdrawals were executed.
Sources Decrypt|Chainalysis
Methodology: compiled from vendor advisories, government feeds (CISA KEV, MSRC), security news sources and on-chain/security-firm alerts. Grouping: one incident, one entry, with every source cited. Unconfirmed reports are labeled. Crypto items are incident reporting, not investment advice. Corrections from prior digests are noted at the top when applicable.