Daily Digest

Zero-Days Exploit, Massive Data Breaches, and AI Theft Dominate Cybersecurity News

September 9, 2026
8 articles (6 new, 2 updated)
24 min read

Summary

Critical Vulnerabilities Under Active Exploitation:

  • [UPDATE] Clop Group Claims Massive Data Heist from Shell, Philips, GE via PTC Flaw: The Clop group is reportedly using JSP web shells for persistence after exploiting CVE-2026-12569 in PTC Windchill and FlexPLM systems. Defenders should monitor for new JSP files in web directories, suspicious web server child processes, and web server logs indicating command execution.
  • [UPDATE] Adobe Commerce Hit by 'StyleSmuggler' Zero-Day Exploited in the Wild: CISA has added CVE-2026-75650, a zero-day affecting Adobe Commerce and Magento Open Source, to its Known Exploited Vulnerabilities catalog due to active exploitation. Federal agencies must remediate by September 22, 2026, highlighting the urgency for all organizations to patch.
  • [NEW] Microsoft's Record September Patch Tuesday Fixes 974 Flaws, Two Zero-Days: Microsoft's September update addresses 974 vulnerabilities, including two actively exploited zero-days (CVE-2026-81963 and CVE-2026-85880) that grant SYSTEM-level access. The release also contains fixes for numerous wormable remote code execution vulnerabilities.

New Threats and Advisories:

  • [NEW] US Agencies: China-Based Firms Stealing US AI Models at Scale: A joint advisory from the NSA, CISA, and FBI accuses six China-based AI companies of stealing U.S. AI models through large-scale querying, potentially violating terms of service and involving government awareness.
  • [NEW] LHC Group Discloses Health Data Breach Affecting Over 162,000: LHC Group reported a data breach impacting 162,578 individuals due to a vishing attack that compromised employee credentials. The stolen credentials were used to access a third-party vendor's platform, leading to the exfiltration of sensitive patient data.
  • [NEW] ShinyHunters Demands $55M After Stealing 200M+ Health Records: The ShinyHunters group claims to have stolen over 200 million health records and is demanding a $55 million ransom. The attack involved vishing, Okta SSO compromise, and subsequent access to Salesforce and Snowflake cloud environments.
  • [NEW] CISA Warns of Hard-Coded Credential in CareCam Pro IP Cameras: CISA issued an ICS advisory for CVE-2026-85083, a hard-coded credential vulnerability in CareCam Pro IP cameras. This flaw could allow an attacker with physical access to gain privileged control of the camera's bootloader and firmware.
  • [NEW] Cybercrime Group Uses YouTube Gaming Lures in Massive PPI Scheme: A Unit 42 investigation identified a cybercrime operation using YouTube gaming lures and SEO poisoning to distribute a malware loader. This loader has been observed delivering various payloads, including new RATs and hijackers, to enterprise and government environments.

Filter by Category

New Articles (6)

Updated Articles (2)

📢 Share This Publication

Help others stay informed about cybersecurity threats

📅 Daily Edition

Curated and deduplicated every day from dozens of trusted sources — giving you one clean, consolidated view of what matters in cybersecurity.

🔢 Deduplication Applied

Related stories are merged into a single evolving article rather than repeated as separate entries — cutting through noise so you only read what's new.

🔗 Full Articles Linked

Every entry links to its full enriched article — complete with MITRE ATT&CK mappings, extracted IOCs, and actionable detection and mitigation guidance.